Wireshark-bugs: [Wireshark-bugs] [Bug 12552] New: Wireshark dissects T.38 ECM image data as HDLC

Date: Tue, 21 Jun 2016 20:39:52 +0000
Bug ID 12552
Summary Wireshark dissects T.38 ECM image data as HDLC
Product Wireshark
Version 2.0.4
Hardware x86
OS Windows 7
Status UNCONFIRMED
Severity Normal
Priority Low
Component Dissection engine (libwireshark)
Assignee [email protected]
Reporter [email protected]

Created attachment 14674 [details]
Capture of T.38 fax call with ECM enabled.

Build Information:
Version 2.0.4 (v2.0.4-0-gdd7746e from master-2.0)

Copyright 1998-2016 Gerald Combs <[email protected]> and contributors.
License GPLv2+: GNU GPL version 2 or later
<http://www.gnu.org/licenses/old-licenses/gpl-2.0.html>
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

Compiled (64-bit) with Qt 5.3.2, with WinPcap (4_1_3), with libz 1.2.8, with
GLib 2.42.0, with SMI 0.4.8, with c-ares 1.11.0, with Lua 5.2, with GnuTLS
3.2.15, with Gcrypt 1.6.2, with MIT Kerberos, with GeoIP, with QtMultimedia,
with AirPcap.

Running on 64-bit Windows 7 Service Pack 1, build 7601, with locale C, with
WinPcap version 4.1.3 (packet.dll version 4.1.0.2980), based on libpcap version
1.0 branch 1_0_rel0b (20091008), with GnuTLS 3.2.15, with Gcrypt 1.6.2, without
AirPcap.
Intel(R) Core(TM) i7-4790 CPU @ 3.60GHz (with SSE4.2), with 16290MB of physical
memory.


Built using Microsoft Visual C++ 12.0 build 40629
--
When T.30 Error Correction Mode (ECM) is enabled, Wireshark attempts to dissect
T.38 packets containing image data as though they contained HDLC messages. For
example, in the attached pcap file, frames 358 through 360 are reassembled as
"FTT - Failure To Train". This information is displayed in the main window and
also in the flow diagram.


You are receiving this mail because:
  • You are watching all bug changes.