Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 2456] New: Incorrect decoding of DST MAC address of frame

Date: Sun, 13 Apr 2008 18:44:15 -0700 (PDT)
http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2456

           Summary: Incorrect decoding of DST MAC address of frame
                    containing ICMPv6 Echo Request
           Product: Wireshark
           Version: 1.0.0
          Platform: PC
               URL: http://www.cs.berkeley.edu/~kfall/priv/ping6-mdns.tr
        OS/Version: Windows XP
            Status: NEW
          Severity: Normal
          Priority: Medium
         Component: Wireshark
        AssignedTo: wireshark-bugs@xxxxxxxxxxxxx
        ReportedBy: kfall@xxxxxxxxxxxxxxx


Build Information:
Version 1.0.0

Copyright 1998-2008 Gerald Combs <gerald@xxxxxxxxxxxxx> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

Compiled with GTK+ 2.12.8, with GLib 2.14.6, with WinPcap (version unknown),
with libz 1.2.3, without POSIX capabilities, with libpcre 7.0, with SMI 0.4.5,
with ADNS, with Lua 5.1, with GnuTLS 1.6.1, with Gcrypt 1.2.3, with MIT
Kerberos, with PortAudio V19-devel, with AirPcap.

Running on Windows XP Service Pack 2, build 2600, with WinPcap version 4.0.2
(packet.dll version 4.0.0.1040), based on libpcap version 0.9.5, without
AirPcap.

Built using Microsoft Visual C++ 6.0 build 8804

Wireshark is Open Source Software released under the GNU General Public
License.

Check the man page and http://www.wireshark.org for more information.
--
In my trace file (created by tcpdump -w), there is an ICMPv6 Echo Request sent
to the IPv6 multicast address FF02::FB contained in a conventional Ethernet
frame with destination MAC address 33:33:00:00:00:fb.  Wireshark labels this
(incorrectly) as IPv6-Neighbor-Discovery_00:00:00:fb.  The packet is indeed
IPv6/ICMPv6, but it is not a neighbor discovery (it is an Echo Request).  The
URL associated with this report is the trace file.


-- 
Configure bugmail: http://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.