CVE-2020-25863: Debian Linux
High severity, CVSS 7.5. EPSS: 4.9% chance of exploitation in the next 30 days.
In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was addressed in epan/dissectors/packet-multipart.c by correcting the deallocation of invalid MIME parts.
Affected products
- Debian Debian Linux: version 9.0 only
- Fedoraproject Fedora: version 31 only; version 32 only; version 33 only
- Opensuse Leap: version 15.1 only; version 15.2 only
- Oracle ZFS Storage Appliance Firmware: version 8.8 only
- Wireshark Wireshark: from 2.6.0, up to and including 2.6.20; from 3.0.0, up to and including 3.0.13; from 3.2.0, up to and including 3.2.6
Published 2020-10-06. Last modified 2026-06-17.