Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: [Wireshark-dev] Wireshark 1.06 crashes in libwireshark.dll when decoding CPHA pa

From: Marty Adkins <marty@xxxxxxxxxxxxxxx>
Date: Thu, 12 Feb 2009 15:33:06 -0500
Wireshark 1.06 consistently crashes in libwireshark.dll when decoding
a CheckPoint CPHA FWHA_MY_STATE packet.  These are sent to a unicast
IP and multicast MAC, from a source IP of 0.0.0.0.  It seems to have
no problem decoding the CPHA FWHA_IFCONF_REPLY packets that have the
same L2/L3 addresses.

The exception raised is c0000005 at address 005DED34 in libwireshark.dll

Environment is v1.06 with the bundled GTK+ 2.12.8.  WinPcap is 4.1b5.
The crash also occurs with 1.05 with WinPcap 4.02.
OS is Windows XP SP3 with all current patches.

In searching the various list archives, I couldn't find this as a
known problem.  I do have a small capture file that demonstrates this
but will only send that upon request.

- Marty