Wireshark-bugs: [Wireshark-bugs] [Bug 10410] Buildbot crash output: fuzz-2014-08-25-8573.pcap

Date: Tue, 26 Aug 2014 05:16:15 +0000

Comment # 4 on bug 10410 from
Yes, it's Skinny and it still crashes wireshark.
It's this packet (decoded by ver 1.10):

Frame 127: 756 bytes on wire (6048 bits), 756 bytes captured (6048 bits) on
interface 0
    Interface id: 0
    Encapsulation type: Linux cooked-mode capture (25)
    Arrival Time: Apr 27, 2013 21:27:08.750305000 CEST
    [Time shift for this packet: 0.000000000 seconds]
    Epoch Time: 1367090828.750305000 seconds
    [Time delta from previous captured frame: 0.000044000 seconds]
    [Time delta from previous displayed frame: 0.000044000 seconds]
    [Time since reference or first frame: 103.906669000 seconds]
    Frame Number: 127
    Frame Length: 756 bytes (6048 bits)
    Capture Length: 756 bytes (6048 bits)
    [Frame is marked: False]
    [Frame is ignored: False]
    [Protocols in frame: sll:ip:tcp:skinny]
Linux cooked capture
    Packet type: Sent by us (4)
    Link-layer address type: 1
    Link-layer address length: 6
    Source: d0:27:88:19:58:fe (d0:27:88:19:58:fe)
    Protocol: IP (0x0800)
Internet Protocol Version 4, Src: 10.0.0.2 (10.0.0.2), Dst: 10.0.0.30
(10.0.0.30)
    Version: 4
    Header length: 20 bytes
    Differentiated Services Field: 0x68 (DSCP 0x1a: Assured Forwarding 31; ECN:
0x00: Not-ECT (Not ECN-Capable Transport))
        0110 10.. = Differentiated Services Codepoint: Assured Forwarding 31
(0x1a)
        .... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable
Transport) (0x00)
    Total Length: 740
    Identification: 0xca7d (51837)
    Flags: 0x02 (Don't Fragment)
        0... .... = Reserved bit: Not set
        .1.. .... = Don't fragment: Set
        ..0. .... = More fragments: Not set
    Fragment offset: 0
    Time to live: 64
    Protocol: TCP (6)
    Header checksum: 0x590f [validation disabled]
        [Good: False]
        [Bad: False]
    Source: 10.0.0.2 (10.0.0.2)
    Destination: 10.0.0.30 (10.0.0.30)
    [Source GeoIP: Unknown]
    [Destination GeoIP: Unknown]
Transmission Control Protocol, Src Port: 2000 (2000), Dst Port: 35079 (35079),
Seq: 597, Ack: 1668, Len: 688
    Source port: 2000 (2000)
    Destination port: 35079 (35079)
    [Stream index: 21]
    Sequence number: 597    (relative sequence number)
    [Next sequence number: 1285    (relative sequence number)]
    Acknowledgment number: 1668    (relative ack number)
    Header length: 32 bytes
    Flags: 0x018 (PSH, ACK)
        000. .... .... = Reserved: Not set
        ...0 .... .... = Nonce: Not set
        .... 0... .... = Congestion Window Reduced (CWR): Not set
        .... .0.. .... = ECN-Echo: Not set
        .... ..0. .... = Urgent: Not set
        .... ...1 .... = Acknowledgment: Set
        .... .... 1... = Push: Set
        .... .... .0.. = Reset: Not set
        .... .... ..0. = Syn: Not set
        .... .... ...0 = Fin: Not set
    Window size value: 78
    [Calculated window size: 9984]
    [Window size scaling factor: 128]
    Checksum: 0xdbd8 [validation disabled]
        [Good Checksum: False]
        [Bad Checksum: False]
    Urgent Pointer: 0x0065 [should be 0x0000 because URG flag is not set]
        [Expert Info (Warn/Protocol): Urgent Pointer: Broken TCP. The urgent
pointer field is nonzero while the URG flag is not set]
            [Message: Urgent Pointer: Broken TCP. The urgent pointer field is
nonzero while the URG flag is not set]
            [Severity level: Warn]
            [Group: Protocol]
    Options: (12 bytes), No-Operation (NOP), No-Operation (NOP)
        No-Operation (NOP)
            Type: 1
                0... .... = Copy on fragmentation: No
                .00. .... = Class: Control (0)
                ...0 0001 = Number: No-Operation (NOP) (1)
        No-Operation (NOP)
            Type: 1
                0... .... = Copy on fragmentation: No
                .00. .... = Class: Control (0)
                ...0 0001 = Number: No-Operation (NOP) (1)
        Timestamps (option length = 11 bytes says option goes past end of
options)
    [SEQ/ACK analysis]
        [Bytes in flight: 688]
    [PDU Size: 688]
Skinny Client Control Protocol
    Data length: 680
    Header version: CM7 type B (0x00000011)
    Message ID: SoftKeyTemplateResMessage (0x00000108)
    Soft-Key offset: 0
    Soft-keys count: 32
    Total soft-keys count: 32
    Soft-key label: \200\001
    Soft-key event: Redial (1)
    Soft-key label: \200\002
    Soft-key event: NewCall (2)
    Soft-key label: \200\003%
    Soft-key event: Hold (3)
    Soft-key label: \200\004
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)
    Soft-key label:
\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252\252
    Soft-key event: Unknown (2863311530)

0000  00 04 00 01 00 06 d0 27 88 19 58 fe 00 00 08 00   .......'..X.....
0010  45 68 02 e4 ca 7d 40 00 40 06 59 0f 0a 00 00 02   Eh...}@[email protected].....
0020  0a 00 00 1e 07 d0 89 07 ed d3 d1 c6 49 d5 4d da   ............I.M.
0030  80 18 00 4e db d8 00 65 01 01 08 0b 00 36 05 05   ...N...e.....6..
0040  ff ff ac ac a8 02 00 00 11 00 00 00 08 01 00 00   ................
0050  00 00 00 00 20 00 00 00 20 00 00 00 80 01 00 00   .... ... .......
0060  00 00 00 00 00 25 00 00 00 00 00 00 01 00 00 00   .....%..........
0070  80 02 00 00 25 00 00 00 00 00 00 00 00 00 00 00   ....%...........
0080  02 00 00 00 80 03 25 00 00 00 fa 00 00 00 00 00   ......%.........
0090  00 00 00 00 03 00 00 00 80 04 00 00 00 00 00 00   ................
00a0  00 00 00 00 00 00 00 00 aa aa aa aa aa aa aa aa   ................
00b0  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
00c0  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
00d0  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
00e0  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
00f0  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
0100  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
0110  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
0120  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
0130  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
0140  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
0150  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
0160  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
0170  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
0180  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
0190  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
01a0  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
01b0  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
01c0  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
01d0  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
01e0  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
01f0  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
0200  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
0210  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
0220  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
0230  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
0240  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
0250  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
0260  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
0270  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
0280  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
0290  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
02a0  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
02b0  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
02c0  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
02d0  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
02e0  aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa   ................
02f0  aa aa aa aa                                       ....


You are receiving this mail because:
  • You are watching all bug changes.