Wireshark-users: Re: [Wireshark-users] bad UDP reassembly

From: Graham Bloice <graham.bloice@xxxxxxxxxxxxx>
Date: Tue, 17 Oct 2017 16:43:39 +0100


On 17 October 2017 at 15:51, Deny IP Any Any <denyipanyany@xxxxxxxxx> wrote:
I have a capture, which I believe shows a device fragmenting UDP packets and not setting the 'More Fragment's flags correctly. Wireshark reassembles the packets, but the 'length' column is not correct for this packet.

I would expect Wireshark to show an error or indicate that there is something wrong with the packets, but it doesn't. Can I send this small capture to someone else to confirm?

using wireshark 2.4.1 on Win64.

--
deny ip any any (4393649193 matches)

The Wireshark Bugzilla is the place for that, where you can attach the capture to the item you raise: https://bugs.wireshark.org

--
Graham Bloice