Описание
QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 1:2.11+dfsg-1ubuntu7.26 |
| devel | not-affected | 1:4.2-3ubuntu1 |
| eoan | released | 1:4.0+dfsg-0ubuntu9.6 |
| esm-infra-legacy/trusty | released | 2.0.0+dfsg-2ubuntu1.47+esm4 |
| esm-infra/bionic | released | 1:2.11+dfsg-1ubuntu7.26 |
| esm-infra/focal | not-affected | 1:4.2-3ubuntu1 |
| esm-infra/xenial | released | 1:2.5+dfsg-5ubuntu10.44 |
| focal | not-affected | 1:4.2-3ubuntu1 |
| groovy | not-affected | 1:4.2-3ubuntu1 |
| hirsute | not-affected | 1:4.2-3ubuntu1 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | DNE | |
| eoan | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| hirsute | DNE | |
| impish | DNE | |
| jammy | DNE |
Показывать по
2.7 Low
CVSS2
3.5 Low
CVSS3
Связанные уязвимости
QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd.
QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd.
QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle. ...
QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd.
Уязвимость функции zrle_compress_data программного обеспечения для эмуляции аппаратного обеспечения различных платформ QEMU, связанная с неправильным освобождением памяти перед удалением последней ссылки, позволяющая нарушителю вызвать отказ в обслуживании
2.7 Low
CVSS2
3.5 Low
CVSS3