Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: [Wireshark-users] UDP Fragmentation Porblem

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: "Keith French" <keithfrench@xxxxxxxxxxxxx>
Date: Thu, 5 Apr 2007 09:16:26 +0100

Wireshark versions 0.99.4 & 0.99.5 seem to have a problem with UDP fragmentation. Earlier versions were fine.
 
It reports bad UDP lengths on all the reassembled fragmented packets which is incorrect.

For example it shows the length field to be 6266 in UDP header, which is correct according to the data + header. However, it reports this as bogus saying it should be 346.
 
In the summary window it reports it as having a "Bad UDP length 6266 > IP Length"
 
As a workaround if you turn off:-
 
"Reassemble Fragmented IP Datagrams" in the IP preferences it is OK.
 
Is this a bug?
  • Follow-Ups:
    • Re: [Wireshark-users] UDP Fragmentation Porblem
      • From: Jeff Morriss
  • Prev by Date: [Wireshark-users] Decoding MMS/COTP/TPKT/TCP
  • Next by Date: Re: [Wireshark-users] UDP Fragmentation Porblem
  • Previous by thread: Re: [Wireshark-users] Decoding MMS/COTP/TPKT/TCP
  • Next by thread: Re: [Wireshark-users] UDP Fragmentation Porblem
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation