Helps if you can attach a sample capture file.
>The heuristic for SIP doesn't do any validation before passing the data to the main SIP dissector:
Yes, thank you for pointing out where it happens, pretty thin-layer of heuristics, indeed ;-).
You could disable protocol "sip_udp" to prevent it from being called.
We cannot, as this would disable it over well-known UDP port 5060 as well and there we would like to keep it.
Instead of all these contortions why not to introduce the logic matching the one for TCP ports ? Seems pretty natural and general to me.
Kind Regards
Ariel Burbaickij
Sent via: Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>