ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-bugs: [Wireshark-bugs] [Bug 3269] New: Wireshark 1.06 crashes in libwireshark.dll when

Date: Sat, 21 Feb 2009 06:44:27 -0800 (PST)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3269

           Summary: Wireshark 1.06 crashes in libwireshark.dll when decoding
                    CPHA packet
           Product: Wireshark
           Version: 1.0.6
          Platform: PC
        OS/Version: Windows XP
            Status: NEW
          Severity: Major
          Priority: Low
         Component: Wireshark
        AssignedTo: wireshark-bugs@xxxxxxxxxxxxx
        ReportedBy: marty@xxxxxxxxxxxxxxx


Build Information:
wireshark 1.0.6 (SVN Rev 27387)

Copyright 1998-2009 Gerald Combs <gerald@xxxxxxxxxxxxx> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

Compiled with GTK+ 2.12.8, with GLib 2.14.6, with WinPcap (version unknown),
with libz 1.2.3, without POSIX capabilities, with libpcre 7.0, with SMI 0.4.8,
with ADNS, with Lua 5.1, with GnuTLS 2.6.3, with Gcrypt 1.4.3, with MIT
Kerberos, with PortAudio V19-devel, with AirPcap.

Running on Windows XP Service Pack 3, build 2600, with WinPcap version 4.1
beta5

(packet.dll version 4.1.0.1452), based on libpcap version 1.0.0, without
AirPcap.

Built using Microsoft Visual C++ 6.0 build 8804

--
Wireshark 1.06 consistently crashes in libwireshark.dll when decoding
a CheckPoint CPHA FWHA_MY_STATE packet.  These are sent to a unicast
IP and multicast MAC, from a source IP of 0.0.0.0.  It seems to have
no problem decoding the CPHA FWHA_IFCONF_REPLY packets that have the
same L2/L3 addresses.

The exception raised is c0000005 at address 005DED34 in libwireshark.dll

Environment is v1.06 with the bundled GTK+ 2.12.8.  WinPcap is 4.1b5.
The crash also occurs with 1.05 with WinPcap 4.02.
OS is Windows XP SP3 with all current patches.

In searching the various list archives, I couldn't find this as a
known problem.  I do have a small capture file that demonstrates this
but will only send that upon request.


-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.