Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 5343] New: Incorrect decoding of S1AP packets

Date: Wed, 27 Oct 2010 13:04:58 -0700 (PDT)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5343

           Summary: Incorrect decoding of S1AP packets
           Product: Wireshark
           Version: 1.2.12
          Platform: Other
        OS/Version: All
            Status: NEW
          Severity: Major
          Priority: Low
         Component: Wireshark
        AssignedTo: wireshark-bugs@xxxxxxxxxxxxx
        ReportedBy: psfales@xxxxxxxxxxxxxxxxxx


Build Information:
TShark 1.2.12

Copyright 1998-2010 Gerald Combs <gerald@xxxxxxxxxxxxx> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

Compiled (32-bit) with GLib 2.17.7, with libpcap 1.1.1, with libz 1.2.3,
without
POSIX capabilities, without libpcre, without SMI, without c-ares, with ADNS,
without Lua, without GnuTLS, with Gcrypt 1.2.2, without Kerberos, without
GeoIP.

Running on Linux 2.4.20-46.7.legacysmp, with libpcap version 1.1.1, Gcrypt
1.2.2.

Built using gcc 3.4.6.

--
The attached capture file contains an S1AP packet which is correctly decoded by
wireshark-1.1.4, 1.2.0, 1.2.1, 1.2.2, 1.2.4, and (I'm told) 1.4.1.   However,
it is reported as a malformed packet by  1.2.11 and 1.2.12.  1.2.10 cores due
to bug 5072.  (Those are the versions I have convenient access to - not sure
about the versions between 1.2.4 and 1.2.10

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.