Wireshark-bugs: [Wireshark-bugs] [Bug 6755] slow loading/processing of conversations with over 5

Date: Fri, 27 Jan 2012 03:51:02 -0800 (PST)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6755

--- Comment #18 from Cristian Constantin <const.crist@xxxxxxxxxxxxxx> 2012-01-27 03:51:01 PST ---
(In reply to comment #16)
> (In reply to comment #15)
> > (In reply to comment #14)
> > > (In reply to comment #10)
> > > > Created attachment 7736 [details]
> > > > screenshoot of problem with the patch
> > > > 
> > > > when I apply the patch to SVN 40488 then wireshark (libwireshark.dll) crash 
> > > > during load of some SIP-TLS captures, attached is a 
> > > > screenshoot. Problem does not occur with a SIP-TLS 
> > > > captures. If I revert the patch, all is fine.
> > > > I'll try to find a unconfidential pcap to provide it for analyse
> > > > 
> > > > tested with XP 32bit
> > > 
> > > cristian: pls. either:
> > > 
> > > 1. provide a capture that produces this problem
> > > 2. run it on a linux/unix machine and send me a backtrace from
> > > the coredump.
> > > 
> > > a. to produce the coredump, make sure you did:
> > > ulimit -c unlimited
> > > before running patched wireshark
> > > 
> > > b. to get the backtrace use gdb on the coredump like this:
> > > gdb .libs/lt-wireshark core
> > > and then under the gdb prompt use "bt" to get the trace.
> > > 
> > > (on some systems the cores are dumped with pre-configured names,
> > > spec'ed in: /proc/sys/kernel/core_pattern)
> > 
> > Hi Cristian,
> > 
> > some more details about the crash: 
> > 
> > it happens on "tcp port number reused" means same IPs:ports, but new tcp
> > sequence.
> > 
> > does it help? I'll try to find a capture asap
> > 
> > regards,
> > Andreas
> 
> I googled this capture with "tcp port number reused" which create the same
> crash.... 
> 
> https://supportforums.cisco.com/servlet/JiveServlet/download/3494413-117425/capthis_out.pcap.zip

cristian: yeap. I have most likely reproduced the problem and got the core.
I am looking into it.

thanks for testing!
bye now!
cristian

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are watching all bug changes.