Wireshark-bugs: [Wireshark-bugs] [Bug 10502] Capture files from a remote virtual interface on Ma
Date: Thu, 25 Sep 2014 18:53:04 +0000

Comment # 4 on bug 10502 from
No, it's definitely a bug in Wireshark - but it's not a bug in Wireshark's
*capture* code, it's a bug in Wireshark's *dissection* code.

Another tool that captures, and writes out the capture, the same way that
Wireshark does will produce capture files that have the same problem that the
ones produced by Wireshark do.  This includes, for example, libpcap and tcpdump
from tcpdump.org, which doesn't have Apple's special hack to write out pcap-ng
files when capturing on a pktap device.

One workaround would be to capture with OS X's tcpdump.

Or you could download the latest "Wireshark 1.12.2rc0 ... Intel 64.dmg" build
from the automated build section of one of the Wireshark download sites.  Go to
https://www.wireshark.org/download/automated/osx/ and pick the most recent
1.12.2 Intel 64 build.  Those builds have the fix.


You are receiving this mail because:
  • You are watching all bug changes.