CVE-2020-25863: High severity wireshark vulnerability
In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was addressed in epan/dissectors/packet-multipart.c by correcting the deallocation of invalid MIME parts.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-25863?
CVE-2020-25863 is a vulnerability in Wireshark versions 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20 that could cause a crash in the MIME Multipart dissector.
How can I fix CVE-2020-25863?
To fix CVE-2020-25863, upgrade Wireshark to version 2.6.10-1~ubuntu18.04.0+ (for Ubuntu 18.04), 3.2.3-1ubuntu0.1~ (for Ubuntu 20.04), 2.6.10-1~ubuntu14.04.0~ (for Ubuntu 14.04), 2.6.10-1~ubuntu16.04.0+ (for Ubuntu 16.04), 3.2.7-1 (for Ubuntu upstream), or the latest available version for Debian.
How severe is CVE-2020-25863?
CVE-2020-25863 is a vulnerability that could cause a crash in Wireshark and is rated as moderate severity.
What is the source of CVE-2020-25863?
CVE-2020-25863 was discovered in Wireshark.
Where can I find more information about CVE-2020-25863?
You can find more information about CVE-2020-25863 at the following references: [GitLab Commit](https://gitlab.com/wireshark/wireshark/-/commit/5803c7b87b3414cdb8bf502af50bb406ca774482), [GitLab Issue](https://gitlab.com/wireshark/wireshark/-/issues/16741), [Wireshark Security Advisory](https://www.wireshark.org/security/wnpa-sec-2020-11.html).