Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 7364] New: Wireshark fails to reassemble subsequent TCP se

Date: Tue, 12 Jun 2012 21:54:28 -0700 (PDT)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7364

           Summary: Wireshark fails to reassemble subsequent TCP segments
                    in an SMB SET SD request
           Product: Wireshark
           Version: 1.9.x (Experimental)
          Platform: x86
        OS/Version: All
            Status: NEW
          Severity: Major
          Priority: Low
         Component: Wireshark
        AssignedTo: bugzilla-admin@xxxxxxxxxxxxx
        ReportedBy: realrichardsharpe@xxxxxxxxx


Build Information:
Version 1.9.0 (SVN Rev 43186 from /trunk)

Copyright 1998-2012 Gerald Combs <gerald@xxxxxxxxxxxxx> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

Compiled (64-bit) with GTK+ 2.22.0, with Cairo 1.10.2, with Pango 1.28.1, with
GLib 2.26.0, with libpcap, with libz 1.2.5, with POSIX capabilities (Linux),
without SMI, without c-ares, without ADNS, without Lua, without Python, with
GnuTLS 2.8.6, with Gcrypt 1.4.5, with MIT Kerberos, without GeoIP, without
PortAudio, with AirPcap.

Running on Linux 2.6.35.14-106.fc14.x86_64, with locale en_US.utf8, with
libpcap
version 1.1.1, with libz 1.2.5, GnuTLS 2.8.6, Gcrypt 1.4.5, without AirPcap.

Built using gcc 4.5.1 20100924 (Red Hat 4.5.1-4).

Wireshark is Open Source Software released under the GNU General Public
License.

Check the man page and http://www.wireshark.org for more information.
--
In the attached capture, frames 7, 8 and 10 are parts of the same SMB SET SD
request.

However, frames 8 and 10 are not reassembled, which causes Wireshark to fail to
dissect the request properly.

Frame 8 is labelled as a Session message and frame 10 as an NBSS Continuation
Message (with inconsistent capitalization.)

I have no patches for this yet. I am just filing the bug.

Capture and screen shot as attachments.

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are watching all bug changes.