ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-dev: Re: [Wireshark-dev] Wireshark 1.06 crashes in libwireshark.dll when decoding CPH

From: Bill Meier <wmeier@xxxxxxxxxxx>
Date: Fri, 13 Feb 2009 10:21:57 -0500
Marty Adkins wrote:
Wireshark 1.06 consistently crashes in libwireshark.dll when decoding
a CheckPoint CPHA FWHA_MY_STATE packet.  These are sent to a unicast
IP and multicast MAC, from a source IP of 0.0.0.0.  It seems to have
no problem decoding the CPHA FWHA_IFCONF_REPLY packets that have the
same L2/L3 addresses.

The exception raised is c0000005 at address 005DED34 in libwireshark.dll

Environment is v1.06 with the bundled GTK+ 2.12.8.  WinPcap is 4.1b5.
The crash also occurs with 1.05 with WinPcap 4.02.
OS is Windows XP SP3 with all current patches.

In searching the various list archives, I couldn't find this as a
known problem.  I do have a small capture file that demonstrates this
but will only send that upon request.

- Marty

Please open a bug report at bugzilla.wireshark.org.

The capture file can be attached to the bug report.

Note that, if desired, you can tick the boxes for
'Private bugs and attachments' and 'Wireshark core' to keep the information private.

Thanks