Wireshark-bugs: [Wireshark-bugs] [Bug 10369] New: ISDN packets incorrectly decode	as RSL
      
      
    
    
        
          | Bug ID | 10369 | 
        
          | Summary | ISDN packets incorrectly decode as RSL | 
        
          | Product | Wireshark | 
        
          | Version | 1.12.0 | 
        
          | Hardware | x86 | 
        
          | OS | Windows 7 | 
        
          | Status | UNCONFIRMED | 
        
          | Severity | Major | 
        
          | Priority | Low | 
        
          | Component | Dissection engine (libwireshark) | 
        
          | Assignee | bugzilla-admin@wireshark.org | 
        
          | Reporter | colin.haywood@metaswitch.com | 
      
        
        Created attachment 12983 [details]
Extract from packet capture of ISDN traffic.
Build Information:
Version 1.12.0 (v1.12.0-0-g4fab41a from master-1.12)
Copyright 1998-2014 Gerald Combs <gerald@wireshark.org> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
Compiled (64-bit) with GTK+ 2.24.23, with Cairo 1.10.2, with Pango 1.34.0, with
GLib 2.38.0, with WinPcap (4_1_3), with libz 1.2.5, with SMI 0.4.8, with c-ares
1.9.1, with Lua 5.2, without Python, with GnuTLS 3.1.22, with Gcrypt 1.6.0,
without Kerberos, with GeoIP, with PortAudio V19-devel (built Jul 31 2014),
with
AirPcap.
Running on 64-bit Windows 7 Service Pack 1, build 7601, with WinPcap version
4.1.3 (packet.dll version 4.1.0.2980), based on libpcap version 1.0 branch
1_0_rel0b (20091008), GnuTLS 3.1.22, Gcrypt 1.6.0, without AirPcap.
Intel(R) Core(TM) i7-4770 CPU @ 3.40GHz, with 8097MB of physical memory.
Built using Microsoft Visual C++ 10.0 build 40219
--
See attached extract from a packet capture on an SCTP link carrying ISDN
(Q.921) traffic. Wireshark 1.12.0 incorrectly decodes this as RSL (Radio
Signalling Layer) and hence claims all the packets are malformed.
This appears to be a regression, though I'm not sure in what version it was
introduced. My colleague has wireshark 1.6.5 and it decodes fine there.
         
      
      
      You are receiving this mail because:
      
      
          - You are watching all bug changes.