https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=15236

            Bug ID: 15236
           Summary: ISUP (ANSI) packets malformed in WS versions later
                    than 2.4.8
           Product: Wireshark
           Version: 2.6.3
          Hardware: x86
                OS: Windows 10
            Status: UNCONFIRMED
          Severity: Major
          Priority: High
         Component: Dissection engine (libwireshark)
          Assignee: bugzilla-ad...@wireshark.org
          Reporter: ha...@radcom.com
  Target Milestone: ---

Created attachment 16673
  --> https://bugs.wireshark.org/bugzilla/attachment.cgi?id=16673&action=edit
Reference PCAP that demonstrates the problem

Build Information:
Version 2.6.3 (v2.6.3-0-ga62e6c27) 
Copyright 1998-2018 Gerald Combs <ger...@wireshark.org> and contributors.
License GPLv2+: GNU GPL version 2 or later
<http://www.gnu.org/licenses/old-licenses/gpl-2.0.html> This is free software;
see the source for copying conditions. There is NO warranty; not even for
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. 
Compiled (64-bit) with Qt 5.9.5, with WinPcap (4_1_3), with GLib 2.42.0, with
zlib 1.2.11, with SMI 0.4.8, with c-ares 1.14.0, with Lua 5.2.4, with GnuTLS
3.4.11, with Gcrypt 1.7.6, with MIT Kerberos, with MaxMind DB resolver, with
nghttp2 1.14.0, with LZ4, with Snappy, with libxml2 2.9.4, with QtMultimedia,
with AirPcap, with SBC, with SpanDSP, with bcg729. 
Running on 64-bit Windows 10, build 17134, with Intel(R) Core(TM) i5-6200U CPU
@ 2.30GHz (with SSE4.2), with 8072 MB of physical memory, with locale
English_United States.1255, with WinPcap version 4.1.3 (packet.dll version
4.1.0.2980), based on libpcap version 1.0 branch 1_0_rel0b (20091008), with
GnuTLS 3.4.11, with Gcrypt 1.7.6, without AirPcap, binary plugins supported (14
loaded). Built using Microsoft Visual C++ 14.12 build 25835 
Wireshark is Open Source Software released under the GNU General Public
License. 
Check the man page and http://www.wireshark.org for more information. 
--
SS7 IAM is marked as "Malformed packet", the capture was tested in several WS
versions and the problem appears in 2.4.8 onward.

***********************************************************************
Frame 1: 150 bytes on wire (1200 bits), 150 bytes captured (1200 bits)
Ethernet II, Src: Microtel_10:04:04 (f0:6e:32:10:04:04), Dst: fa:16:3e:49:a1:bc
(fa:16:3e:49:a1:bc)
Internet Protocol Version 4, Src: 10.0.0.1, Dst: 10.0.0.2
Stream Control Transmission Protocol, Src Port: 2904 (2904), Dst Port: 2904
(2904)
MTP 2 User Adaptation Layer
Message Transfer Part Level 3
ISDN User Part
[Malformed Packet: ISUP]
    [Expert Info (Error/Malformed): Malformed Packet (Exception occurred)]
        [Malformed Packet (Exception occurred)]
        <Message: Malformed Packet (Exception occurred)>
        [Severity level: Error]
        [Group: Malformed]
    <Malformed Packet>
***********************************************************************

reference PCAP attached.

-- 
You are receiving this mail because:
You are watching all bug changes.
___________________________________________________________________________
Sent via:    Wireshark-bugs mailing list <wireshark-bugs@wireshark.org>
Archives:    https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
             mailto:wireshark-bugs-requ...@wireshark.org?subject=unsubscribe

Reply via email to