Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 1001] free() invalid pointer in dissect_802_3 at packet-ie

Date: Sat, 29 Jul 2006 11:07:01 +0000 (GMT)
http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1001





------- Comment #17 from gentoo-a7x@xxxxxxxxxxxxxxx  2006-07-29 11:07 GMT -------
(In reply to comment #14)
> Interesting news:  I have two packet captures, one of which crashes Wireshark,
> while the other does not.  The one that crashes Wireshark has only spanning
> tree protocol packets, while the other has only TCP and UDP packets.

I have confirmed that wireshark/tshark crash the instant a spanning tree
protocol packet is displayed.  I started a large download and then started a
capture in wireshark with all dissectors turned off.  I stopped the capture
after a few seconds and then searched for the first non-IP packet by using the
display filter "data[12]!=08 || data[13]!=00" and made a mental note of the
packet number (which happened to be 1151).  I then loaded the pcap file in
tshark and noticed that it crashed right after displaying packet number 1150.


-- 
Configure bugmail: http://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.