First published: Tue Oct 06 2020(Updated: )
In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was addressed in epan/dissectors/packet-multipart.c by correcting the deallocation of invalid MIME parts.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/wireshark | <2.6.10-1~ubuntu18.04.0+ | 2.6.10-1~ubuntu18.04.0+ |
ubuntu/wireshark | <3.2.3-1ubuntu0.1~ | 3.2.3-1ubuntu0.1~ |
ubuntu/wireshark | <2.6.10-1~ubuntu14.04.0~ | 2.6.10-1~ubuntu14.04.0~ |
ubuntu/wireshark | <2.6.10-1~ubuntu16.04.0+ | 2.6.10-1~ubuntu16.04.0+ |
ubuntu/wireshark | <3.2.7-1 | 3.2.7-1 |
debian/wireshark | 2.6.20-0+deb10u4 2.6.20-0+deb10u8 3.4.10-0+deb11u1 4.0.11-1~deb12u1 4.2.2-1 4.2.2-1.1 | |
Wireshark Wireshark | >=2.6.0<=2.6.20 | |
Wireshark Wireshark | >=3.0.0<=3.0.13 | |
Wireshark Wireshark | >=3.2.0<=3.2.6 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 | |
openSUSE | =15.1 | |
openSUSE | =15.2 | |
Debian Debian Linux | =9.0 | |
All of | ||
oracle zfs storage appliance firmware | =8.8 | |
Oracle Sun ZFS Storage Appliance Kit | ||
oracle zfs storage appliance firmware | =8.8 | |
Oracle Sun ZFS Storage Appliance Kit |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25863 is a vulnerability in Wireshark versions 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20 that could cause a crash in the MIME Multipart dissector.
To fix CVE-2020-25863, upgrade Wireshark to version 2.6.10-1~ubuntu18.04.0+ (for Ubuntu 18.04), 3.2.3-1ubuntu0.1~ (for Ubuntu 20.04), 2.6.10-1~ubuntu14.04.0~ (for Ubuntu 14.04), 2.6.10-1~ubuntu16.04.0+ (for Ubuntu 16.04), 3.2.7-1 (for Ubuntu upstream), or the latest available version for Debian.
CVE-2020-25863 is a vulnerability that could cause a crash in Wireshark and is rated as moderate severity.
CVE-2020-25863 was discovered in Wireshark.
You can find more information about CVE-2020-25863 at the following references: [GitLab Commit](https://gitlab.com/wireshark/wireshark/-/commit/5803c7b87b3414cdb8bf502af50bb406ca774482), [GitLab Issue](https://gitlab.com/wireshark/wireshark/-/issues/16741), [Wireshark Security Advisory](https://www.wireshark.org/security/wnpa-sec-2020-11.html).