Wireshark-bugs: [Wireshark-bugs] [Bug 10233] New: Wireshark crashes if Lua heuristic dissector r

Date: Thu, 26 Jun 2014 16:41:48 +0000
Bug ID 10233
Summary Wireshark crashes if Lua heuristic dissector returns true
Classification Unclassified
Product Wireshark
Version Git
Hardware x86-64
OS Windows 7
Status UNCONFIRMED
Severity Major
Priority Low
Component Dissection engine (libwireshark)
Assignee [email protected]
Reporter [email protected]

Build Information:
Compiled (64-bit) with GTK+ 2.24.23, with Cairo 1.10.2, with Pango 1.34.0, with
GLib 2.38.0, with WinPcap (4_1_3), with libz 1.2.5, with SMI 0.4.8, with c-ares
1.9.1, with Lua 5.2, with GnuTLS 3.1.22, with Gcrypt 1.6.0, without Kerberos,
with GeoIP, with PortAudio V19-devel (built Jun 23 2014), with AirPcap.

Running on 64-bit Windows 7 Service Pack 1, build 7601, with WinPcap version
4.1.3 (packet.dll version 4.1.0.2980), based on libpcap version 1.0 branch
1_0_rel0b (20091008), GnuTLS 3.1.22, Gcrypt 1.6.0, without AirPcap.
       Intel(R) Core(TM) i5-2540M CPU @ 2.60GHz (with SSE4.2), with 8072MB of
physical memory.


Built using Microsoft Visual C++ 10.0 build 30319

--
As the title says, Wireshark crashes if a Lua heuristic dissector returns true.

Easy steps to reproduce (assuming your version of Wireshark already has Lua
support):

1) Visit http://wiki.wireshark.org/Lua/Examples and download the sample
dissector.lua and dns_port.pcap files.

2) Edit dissector.lua, changing the default settings as follows so that
heuristics are enabled and heur_dissect_dns() is guaranteed to be called:

    SETTING         OLD       NEW
    port            65333     64333
    heur_enabled    FALSE*    true

    *presumably this should have been false?

3) Copy dissector.lua into <personal configuration>\plugins\ folder.
4) Start Wireshark.
5) Load the dns_port.pcap file into Wireshark.  ==> Crash!


You are receiving this mail because:
  • You are watching all bug changes.