In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was addressed in epan/dissectors/packet-multipart.c by correcting the deallocation of invalid MIME parts.
[
{
"digest": {
"function_hash": "258630385260328047632033345300933775111",
"length": 1016.0
},
"target": {
"function": "get_multipart_info",
"file": "epan/dissectors/packet-multipart.c"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://gitlab.com/wireshark/wireshark@5803c7b87b3414cdb8bf502af50bb406ca774482",
"id": "CVE-2020-25863-6de84241"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"208246242650496814565964424648644299401",
"294694781186209402313729773177228924552",
"296834981432785644725352318342959509753",
"11226755345798513633551516444771710492",
"83657457413707773100325558572280999555",
"331039726917801260391502927505222658143",
"335775844432884418191867112615122104742",
"108215642888986207386480559008634653657",
"38770556514498019418041764396356834770",
"250934303007487353493085030397228745494"
]
},
"target": {
"file": "epan/dissectors/packet-multipart.c"
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"source": "https://gitlab.com/wireshark/wireshark@5803c7b87b3414cdb8bf502af50bb406ca774482",
"id": "CVE-2020-25863-e55649ab"
}
]