Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 9835] New: SIP/SDP isn't tracking RTP streams

Date: Tue, 04 Mar 2014 20:47:30 +0000
Bug ID 9835
Summary SIP/SDP isn't tracking RTP streams
Classification Unclassified
Product Wireshark
Version 1.10.5
Hardware x86
OS Mac OS X 10.9
Status UNCONFIRMED
Severity Normal
Priority Low
Component Wireshark
Assignee [email protected]
Reporter [email protected]

Build Information:
Version 1.10.5 (SVN Rev Unknown from unknown)

Copyright 1998-2013 Gerald Combs <[email protected]> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

Compiled (64-bit) with GTK+ 2.24.22, with Cairo 1.12.16, with Pango 1.36.1,
with
GLib 2.38.2, with libpcap, with libz 1.2.8, without POSIX capabilities, without
libnl, with SMI 0.4.8, without c-ares, with ADNS, with Lua 5.2, without Python,
with GnuTLS 3.1.10, with Gcrypt 1.5.3, with MIT Kerberos, with GeoIP, with
PortAudio V19-devel (built Feb  8 2014 04:53:37), with AirPcap.

Running on Mac OS X 10.9.2, build 13C64 (Darwin 13.1.0), with locale
en_US.UTF-8, with libpcap version 1.5.3, with libz 1.2.8, GnuTLS 3.1.10, Gcrypt
1.5.3, without AirPcap.
Intel(R) Core(TM) i7 CPU       M 620  @ 2.67GHz

Built using clang 4.2.1 Compatible Apple LLVM 5.0 (clang-500.2.79).

--
Both in v1.10.5 and 1.11.3 the attached capture file does not decode the RTP
stream from the SDP info.  But in 1.8.12 it does.

This came from a ask.wireshark.org thread:
http://ask.wireshark.org/questions/30238/rtp-streams-are-not-visible-in-the-graph

The SDP isn't malformed nor illegal, but it isn't completely "normal" either. 
Regardless, this isn't the only bug in SIP/SDP tracking of conversations, so
the SIP/SDP handlers probably need to be scrubbed (again).

There's another bug as well: bug 9021, which is similar but might be different.

And there's another ask.wireshark thread here that looks like a related bug to
me as well:
http://ask.wireshark.org/questions/20714/rtp-dtmf-digits-are-no-longer-displayed-in-voip-graph-analysis


You are receiving this mail because:
  • You are watching all bug changes.