Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 2992] New: Media stream incorrectly decoded as SRTP instea

Date: Thu, 23 Oct 2008 06:24:09 -0700 (PDT)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2992

           Summary: Media stream incorrectly decoded as SRTP instead of RTP
           Product: Wireshark
           Version: 1.0.0
          Platform: PC
        OS/Version: Windows XP
            Status: NEW
          Severity: Major
          Priority: Medium
         Component: Wireshark
        AssignedTo: wireshark-bugs@xxxxxxxxxxxxx
        ReportedBy: christian.garbin@xxxxxxxxxxx


Build Information:
Version 1.0.0

Copyright 1998-2008 Gerald Combs <gerald@xxxxxxxxxxxxx> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

Compiled with GTK+ 2.12.8, with GLib 2.14.6, with WinPcap (version unknown),
with libz 1.2.3, without POSIX capabilities, with libpcre 7.0, with SMI 0.4.5,
with ADNS, with Lua 5.1, with GnuTLS 1.6.1, with Gcrypt 1.2.3, with MIT
Kerberos, with PortAudio V19-devel, with AirPcap.

Running on Windows XP Service Pack 2, build 2600, with WinPcap version 4.0.2
(packet.dll version 4.0.0.1040), based on libpcap version 0.9.5, without
AirPcap.

Built using Microsoft Visual C++ 6.0 build 8804

Wireshark is Open Source Software released under the GNU General Public
License.

Check the man page and http://www.wireshark.org for more information.
--
Scenario:

- SIP phone at 10.0.131.72 is in conversation with another SIP phone
- In frame 1509 phone gets reINVITE with new SDP offer to point to another
place (a media server for music on hold)
- SDP offer contains AVP and SAVP offers
- In frame 1511 phone selects AVP in the SDP answer by setting SVAP port to
zero
- WireShark decodes media stream as SRTP, intead of RTP. Refer to media stream
between 10.0.131.72 and 10.0.131.70 starting at frame 1523.

Also tested with 1.0.4. Same problem there.


-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.