https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=16778
Bug ID: 16778
Summary: Display Filter Macros Crash Wireshark
Product: Wireshark
Version: 3.2.4
Hardware: x86-64
OS: Windows 10
Status: UNCONFIRMED
Severity: Major
Priority: Low
Component: GTK+ UI
Assignee: [email protected]
Reporter: [email protected]
Target Milestone: ---
Build Information:
3.2.4 (v3.2.4-0-g893b5a5e1e3e)
Compiled (64-bit) with Qt 5.12.8, with WinPcap SDK (WpdPack) 4.1.2, with GLib
2.52.3, with zlib 1.2.11, with SMI 0.4.8, with c-ares 1.15.0, with Lua 5.2.4,
with GnuTLS 3.6.3 and PKCS #11 support, with Gcrypt 1.8.3, with MIT Kerberos,
with MaxMind DB resolver, with nghttp2 1.39.2, with brotli, with LZ4, with
Zstandard, with Snappy, with libxml2 2.9.9, with QtMultimedia, with automatic
updates using WinSparkle 0.5.7, with AirPcap, with SpeexDSP (using bundled
resampler), with SBC, with SpanDSP, with bcg729.
Running on 64-bit Windows Server 2012 R2, build 9600, with Intel(R) Xeon(R) CPU
E5-2690 v4 @ 2.60GHz (with SSE4.2), with 8191 MB of physical memory, with
locale
English_United States.1252, with light display mode, without HiDPI, with Npcap
version 0.9991, based on libpcap version 1.9.1, with GnuTLS 3.6.3, with Gcrypt
1.8.3, with brotli 1.0.2, without AirPcap, binary plugins supported (19
loaded).
Built using Microsoft Visual Studio 2019 (VC++ 14.25, build 28614).
--
When applying combined display filter macros, Wireshark crashes.
Steps to Reproduce:
1. In Analyze > Display Filter Macros, create a complex macro with macros
separated by '&&' or '||'
For example, complex macro 'R4' has the following text ${R:$1} && ${4RS}0
2. Apply the macro in 'Apply a display filter' bar typing in the complex macro
'R4'
3. Press 'Enter' key and Wireshark crashes
Actual Results: Wireshark crashes.
Expected Results: Packet capture is parsed and filtered according to the macro
with no interruptions/crash.
Additional Information/Problem Details: The macros I have been using no longer
works in Wireshark versions 3.2.4 and above.
Problem signature:
Problem Event Name: APPCRASH
Application Name: Wireshark.exe
Application Version: 3.2.4.0
Application Timestamp: 5ec41c5c
Fault Module Name: libwireshark.dll
Fault Module Version: 3.2.4.0
Fault Module Timestamp: 5ec41c39
Exception Code: c0000005
Exception Offset: 000000000008165b
OS Version: 6.3.9600.2.0.0.272.7
Locale ID: 1033
Additional Information 1: 1689
Additional Information 2: 16891ab289e28500f8300ba7607ca943
Additional Information 3: 69e6
Additional Information 4: 69e6627338f68f5749f916380d68c5b9
--
You are receiving this mail because:
You are watching all bug changes.___________________________________________________________________________
Sent via: Wireshark-bugs mailing list <[email protected]>
Archives: https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
mailto:[email protected]?subject=unsubscribe