We're now a non-profit! Support open source packet analysis by making a donation.

Wireshark-users: Re: [Wireshark-users] UDP Fragmentation Porblem

From: Jeff Morriss <jeff.morriss@xxxxxxxxxxx>
Date: Thu, 05 Apr 2007 16:21:24 +0800

Keith French wrote:
Wireshark versions 0.99.4 & 0.99.5 seem to have a problem with UDP fragmentation. Earlier versions were fine. It reports bad UDP lengths on all the reassembled fragmented packets which is incorrect.

For example it shows the length field to be 6266 in UDP header, which is correct according to the data + header. However, it reports this as bogus saying it should be 346. In the summary window it reports it as having a "Bad UDP length 6266 > IP Length" As a workaround if you turn off:- "Reassemble Fragmented IP Datagrams" in the IP preferences it is OK. Is this a bug?

Yes, see bug 1462 in the bugs database. It was fixed shortly after 0.99.5 was released so you can try out one of the buildbot builds if you want.