Wireshark-bugs: [Wireshark-bugs] [Bug 3652] New: fuzz testing crashes tshark, while wireshark re

Date: Fri, 3 Jul 2009 06:43:17 -0700 (PDT)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3652

           Summary: fuzz testing crashes tshark, while wireshark reports
                    dissector bug
           Product: Wireshark
           Version: SVN
          Platform: Other
        OS/Version: All
            Status: NEW
          Severity: Critical
          Priority: High
         Component: Wireshark
        AssignedTo: wireshark-bugs@xxxxxxxxxxxxx
        ReportedBy: yamisoe@xxxxxxxxx


Created an attachment (id=3243)
 --> (https://bugs.wireshark.org/bugzilla/attachment.cgi?id=3243)
the reduced fuzzed capture file

Build Information:
Version 1.3.0 (SVN Rev 28897)

Copyright 1998-2009 Gerald Combs <gerald@xxxxxxxxxxxxx> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

Compiled with GTK+ 2.16.1, with GLib 2.20.1, with libpcap 1.0.0, with libz
1.2.3.3, without POSIX capabilities, without libpcre, without SMI, without
c-ares, without ADNS, with Lua 5.1, without Python, with GnuTLS 2.4.2, with
Gcrypt 1.4.1, without Kerberos, without GeoIP, without PortAudio, without
AirPcap.
NOTE: this build doesn't support the "matches" operator for Wireshark filter
syntax.

Running on Linux 2.6.28-11-generic, with libpcap version 1.0.0, GnuTLS 2.4.2,
Gcrypt 1.4.1.

Built using gcc 4.3.3.

Wireshark is Open Source Software released under the GNU General Public
License.

Check the man page and http://www.wireshark.org for more information.
--
The attached file is the reduced capture file with only 2 packets.

Wireshark says:

21:35:56          Warn Dissector bug, protocol MIOP, in packet 1:
tvbuff.c:1023: failed assertion "length <= 0x7FFFFFFF"
21:35:56          Err  Per-packet memory corrupted.
Aborted


-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.