Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-bugs: [Wireshark-bugs] [Bug 5170] New: Wireshark displays reassembled-packet without the data of last fragment packet

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: bugzilla-daemon@xxxxxxxxxxxxx
Date: Wed, 1 Sep 2010 06:23:28 -0700 (PDT)

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5170

           Summary: Wireshark displays reassembled-packet without the data
                    of last fragment packet
           Product: Wireshark
           Version: unspecified
          Platform: Other
        OS/Version: Windows XP
            Status: NEW
          Severity: Minor
          Priority: Low
         Component: Wireshark
        AssignedTo: wireshark-bugs@xxxxxxxxxxxxx
        ReportedBy: raghutrs@xxxxxxxxx


Build Information:
Copyright 1998-2008 Gerald Combs <gerald@xxxxxxxxxxxxx> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

Compiled with GTK+ 2.12.8, with GLib 2.14.6, with WinPcap (version unknown),
with libz 1.2.3, without POSIX capabilities, with libpcre 7.0, with SMI 0.4.5,
with ADNS, with Lua 5.1, with GnuTLS 1.6.1, with Gcrypt 1.2.3, with MIT
Kerberos, with PortAudio V19-devel, with AirPcap.

Running on Windows XP Service Pack 2, build 2600, with WinPcap version 4.1.1
(packet.dll version 4.1.0.1753), based on libpcap version 1.0 branch 1_0_rel0b
(20091008), without AirPcap.

Built using Microsoft Visual C++ 8.0 build 50727

Wireshark is Open Source Software released under the GNU General Public
License.

Check the man page and http://www.wireshark.org for more information.
--
The problem occurs in following conditions.
-data size of last fragment packet < data size of pre-last fragment packet  &&
-pre-last fragment packet is retransmitted


The following condition will fail for the retransmitted pre-last fragment 
if the size of the last fragment < size of the pre-last fragment  
"fd_i->len + dfpos <= size" where 
fd_i->len : is the size of current fragment, 

dfpos : is the number of bytes copied until now, 
size : is the total number of bytes. 

Since the condition fails, the last fragment is not reassembled.

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.

  • Follow-Ups:
    • [Wireshark-bugs] [Bug 5170] Wireshark displays reassembled-packet without the data of last fragment packet
      • From: bugzilla-daemon
    • [Wireshark-bugs] [Bug 5170] Wireshark displays reassembled-packet without the data of last fragment packet
      • From: bugzilla-daemon
    • [Wireshark-bugs] [Bug 5170] Wireshark displays reassembled-packet without the data of last fragment packet
      • From: bugzilla-daemon
    • [Wireshark-bugs] [Bug 5170] Wireshark displays reassembled-packet without the data of last fragment packet
      • From: bugzilla-daemon
    • [Wireshark-bugs] [Bug 5170] Wireshark displays reassembled-packet without the data of last fragment packet
      • From: bugzilla-daemon
    • [Wireshark-bugs] [Bug 5170] Wireshark displays reassembled-packet without the data of last fragment packet
      • From: bugzilla-daemon
  • Prev by Date: [Wireshark-bugs] [Bug 5169] New: Dissection of uncodocumented AFP func FPSpotlightRPC
  • Next by Date: [Wireshark-bugs] [Bug 5169] Dissection of uncodocumented AFP func FPSpotlightRPC
  • Previous by thread: [Wireshark-bugs] [Bug 5169] Dissection of uncodocumented AFP func FPSpotlightRPC
  • Next by thread: [Wireshark-bugs] [Bug 5170] Wireshark displays reassembled-packet without the data of last fragment packet
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation