CVE-2019-20382

QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd.
Configurations

Configuration 1 (hide)

cpe:2.3:a:qemu:qemu:4.1.0:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

Information

Published : 2020-03-05 19:15

Updated : 2020-07-26 14:15


NVD link : CVE-2019-20382

Mitre link : CVE-2019-20382


JSON object : View

Products Affected

opensuse

  • leap

qemu

  • qemu
CWE
CWE-401

Missing Release of Memory after Effective Lifetime