Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] [BUG] BJNP protocol (maybe overflow)

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Stephen Fisher <steve@xxxxxxxxxxxxxxxxxx>
Date: Sat, 9 Jan 2010 13:19:54 -0700


On Jan 9, 2010, at 6:06 AM, Ershov Pavel wrote:

If you send a packet protocol BJNP (which sends CUPS), then wireshrk displays it incorrectly. When sending multiple identical packets, displaying changes.

Thanks for your report and the sample code to reproduce it! The dissector's code was putting the string in the INFO column and then freeing it without copying it first. I just fixed that in SVN revision 31472 (http://anonsvn.wireshark.org/viewvc?view=rev&revision=31472 ) of the development 1.3.x version of Wireshark. I will put in a request that this fix be copied over to future 1.2.x releases. This dissector is not in the 1.0.x releases.


Steve


  • References:
    • [Wireshark-users] [BUG] BJNP protocol (maybe overflow)
      • From: Ershov Pavel
  • Prev by Date: Re: [Wireshark-users] cursor to the point in packet detail view
  • Next by Date: [Wireshark-users] Creating and Modifying Packets
  • Previous by thread: [Wireshark-users] [BUG] BJNP protocol (maybe overflow)
  • Next by thread: [Wireshark-users] (no subject)
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation