Wireshark-bugs: [Wireshark-bugs] [Bug 10691] New: BACnet protocol: Dissection error after except

Date: Tue, 11 Nov 2014 07:44:07 +0000
Bug ID 10691
Summary BACnet protocol: Dissection error after exception schedule
Product Wireshark
Version 1.8.4
Hardware x86
OS Windows 7
Status UNCONFIRMED
Severity Normal
Priority Low
Component Dissection engine (libwireshark)
Assignee [email protected]
Reporter [email protected]

Created attachment 13251 [details]
Wireshark with one telegram dissection ok, one telegram with failed dissection

Build Information:
Version 1.8.4 (SVNRev 46250 from /trunk-1.8)

Copyright 1998-2012 Gerald Combs <[email protected]> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

Compiled (64-bit) with GTK+ 2.24.10, with Cairo 1.10.2, with Pango 1.30.0, with
GLib 2.32.2, with WinPcap (4_1_2), with libz 1.2.5, without POSIX capabilities,
with SMI 0.4.8, with c-ares 1.7.1, with Lua 5.1, without Python, with GnuTLS
2.12.18, with Gcrypt 1.4.6, without Kerberos, with GeoIP, with PortAudio
V19-devel (built Nov 28 2012), with AirPcap.

Running on 64-bit Windows 7 Service Pack 1, build 7601, with WinPcap version
4.1.2 (packet.dll version 4.1.0.2001), based on libpcap version 1.0 branch
1_0_rel0b (20091008), GnuTLS 2.12.18, Gcrypt 1.4.6, without AirPcap.

Built using Microsoft Visual C++ 10.0 build 40219
--
Analysing BACnet protocol, a ReadPropertyMultiply-ACK.
The ACK contains a list of properties, and property exception-schedule is a
member of the list.
In case the value of the property is empty, the dissection of the following
data is successfull. In case the property value in not empty, the dessection
announces an error (prints "Something is poing wrong here !!") and no more data
is analysed.

See attached capture. The first telegram is that with the empty
exception-schedule value, the second on is that with filled value, that forces
the dissection error. The data of the telegram is valid.


You are receiving this mail because:
  • You are watching all bug changes.