Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 6765] non-IPP packets to or from port 631 are dissected as

Date: Mon, 13 Feb 2012 22:07:50 -0800 (PST)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6765

--- Comment #10 from Guy Harris <guy@xxxxxxxxxxxx> 2012-02-13 22:07:49 PST ---
OK, I've checked in a change in rev 41025 to make the HTTP dissector, if it has
a media type for the entity body, whether there's a dissector for that media
type before trying other ways to pick a dissector.  This matches the way I read
RFC 2068, fixes this bug even with the added checks removed from the IPP
dissector, and, in my regression testing, didn't break anything and fixed some
cases where even TShark with the top-of-trunk IPP dissector didn't work
correctly.

I'll schedule that for 1.6.x and 1.4.x as appropriate.  You could probably just
revert to the old version of the IPP dissector, rather than having the
port-number-based version be the only version that does the extra checks.

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are watching all bug changes.