https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14524

Pascal Quantin <pascal.quan...@gmail.com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
           Severity|Critical                    |Normal
                 CC|                            |pascal.quan...@gmail.com
            Summary|ranap relocation request    |SCCP reassembly bug for
                   |not decode                  |RANAP traffic

--- Comment #1 from Pascal Quantin <pascal.quan...@gmail.com> ---
This seems to be a SCCP reassembly bug. Presumably frame 5 should be
reassembled with frame 3 and 4 and 7, but this is not happening. So the packet
sent to RANAP is too short (529 bytes while the PER encoding indicates an open
type length of 580 bytes), leading to the malformed error.
Someone knowledgeable about SCCP (so not me), should have a look.
At first glance (without knowing anything about the protocol itself) the
payload received by the SCCP layer is not correct: the first bytes are 00 03 00
while it looks like it should be 0605F5A4 followed by a mode data flag set to
0.
Can MTP3 perform fragmentation?

-- 
You are receiving this mail because:
You are watching all bug changes.
___________________________________________________________________________
Sent via:    Wireshark-bugs mailing list <wireshark-bugs@wireshark.org>
Archives:    https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
             mailto:wireshark-bugs-requ...@wireshark.org?subject=unsubscribe

Reply via email to