https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14472

--- Comment #8 from Peter Wu <pe...@lekensteyn.nl> ---
In fact, two packets are sufficient to trigger the issue:

IP()/TCP(sport=8080, dport=2575, flags="A", seq=1)/data1,
IP()/TCP(sport=8080, dport=2575, flags="SA", seq=1+len(data1))/data2,

The first packet is decoded as hl7 (because port 2575 (hl7) < 8080 (http)),
the second packet is decoded as http (because SYN/ACK selects port 8080).

-- 
You are receiving this mail because:
You are watching all bug changes.
___________________________________________________________________________
Sent via:    Wireshark-bugs mailing list <wireshark-bugs@wireshark.org>
Archives:    https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
             mailto:wireshark-bugs-requ...@wireshark.org?subject=unsubscribe

Reply via email to