Unrated severityNVD Advisory· Published Mar 5, 2020· Updated Aug 5, 2024
CVE-2019-20382
CVE-2019-20382
Description
QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd.
Affected products
21- QEMU/QEMUdescription
- osv-coords20 versionspkg:rpm/almalinux/libiscsipkg:rpm/almalinux/libiscsi-develpkg:rpm/almalinux/libiscsi-utilspkg:rpm/almalinux/netcfpkg:rpm/almalinux/netcf-develpkg:rpm/almalinux/netcf-libspkg:rpm/almalinux/sgabiospkg:rpm/almalinux/sgabios-binpkg:rpm/opensuse/qemu&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/qemu-linux-user&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP1pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015
< 1.18.0-8.module_el8.6.0+2880+7d9e3703+ 19 more
- (no CPE)range: < 1.18.0-8.module_el8.6.0+2880+7d9e3703
- (no CPE)range: < 1.18.0-8.module_el8.6.0+2880+7d9e3703
- (no CPE)range: < 1.18.0-8.module_el8.3.0+2048+e7a0a3ea
- (no CPE)range: < 0.2.8-12.module_el8.5.0+2608+72063365
- (no CPE)range: < 0.2.8-12.module_el8.3.0+2048+e7a0a3ea
- (no CPE)range: < 0.2.8-12.module_el8.6.0+2880+7d9e3703
- (no CPE)range: < 1:0.20170427git-3.module_el8.5.0+2608+72063365
- (no CPE)range: < 1:0.20170427git-3.module_el8.5.0+2608+72063365
- (no CPE)range: < 3.1.1.1-lp151.7.12.1
- (no CPE)range: < 3.1.1.1-lp151.7.12.1
- (no CPE)range: < 2.11.2-9.36.1
- (no CPE)range: < 2.11.2-9.36.1
- (no CPE)range: < 3.1.1.1-9.14.1
- (no CPE)range: < 3.1.1.1-9.14.1
- (no CPE)range: < 2.11.2-5.26.1
- (no CPE)range: < 3.1.1.1-3.9.1
- (no CPE)range: < 2.11.2-9.36.1
- (no CPE)range: < 2.11.2-5.26.1
- (no CPE)range: < 3.1.1.1-3.9.1
- (no CPE)range: < 2.11.2-9.36.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- lists.opensuse.org/opensuse-security-announce/2020-04/msg00007.htmlmitrevendor-advisoryx_refsource_SUSE
- usn.ubuntu.com/4372-1/mitrevendor-advisoryx_refsource_UBUNTU
- www.debian.org/security/2020/dsa-4665mitrevendor-advisoryx_refsource_DEBIAN
- www.openwall.com/lists/oss-security/2020/03/05/1mitrex_refsource_MISC
- git.qemu.orgmitrex_refsource_MISC
- lists.debian.org/debian-lts-announce/2020/07/msg00020.htmlmitremailing-listx_refsource_MLIST
News mentions
0No linked articles in our index yet.