Wireshark (64-bit) 歷史版本列表
Ethereal 網絡協議分析儀已經改名為 Wireshark 64 位。名字可能是新的,但軟件是一樣的。 Wireshark 的強大功能使其成為全球網絡故障排除,協議開發和教育的首選工具.Wireshark 是由全球網絡專家撰寫的,是開源功能的一個例子。 Wireshark 64 位被世界各地的網絡專業人士用於分析,故障排除,軟件和協議開發和教育。該程序具有協議分析儀所期望的所有標準功能,以及其... Wireshark (64-bit) 軟體介紹更新時間:2015-05-14
更新細節:
What's new in this version:
The following vulnerabilities have been fixed:
- The LBMR dissector could go into an infinite loop. (Bug 11036) CVE-2015-3808 CVE-2015-3809
- The WebSocket dissector could recurse excessively. (Bug 10989) CVE-2015-3810
- The WCP dissector could crash while decompressing data. (Bug 10978) CVE-2015-3811
- The X11 dissector could leak memory. (Bug 11088) CVE-2015-3812
- The packet reassembly code could leak memory. (Bug 11129) CVE-2015-3813
- The IEEE 802.11 dissector could go into an infinite loop. (Bug 11110) CVE-2015-3814
- The Android Logcat file parser could crash. Discovered by Hanno Böck. (Bug 11188) CVE-2015-3815 The following bugs have been fixed:
- Wireshark crashes if "Update list of packets in real time" is disabled and a display filter is applied while capturing. (Bug 6217)
- EAPOL 4-way handshake information wrong. (Bug 10557)
- RPC NULL calls incorrectly flagged as malformed. (Bug 10646)
- Wireshark relative ISN set incorrectly if raw ISN set to 0. (Bug 10713)
- Buffer overrun in encryption code. (Bug 10849)
- Crash when use Telephony / Voip calls. (Bug 10885)
- ICMP Parameter Problem message contains Length of original datagram is treated as the total IPv4 length. (Bug 10991)
- ICMP Redirect takes 4 bytes for IPv4 payload instead of 8. (Bug 10992)
- Missing field "tcp.pdu.size" in TCP stack. (Bug 11007)
- Sierra EM7345 marks MBIM packets as NCM. (Bug 11018)
- Possible infinite loop DoS in ForCES dissector. (Bug 11037)
- "Decode As…" crashes when a packet dialog is open. (Bug 11043)
- Interface Identifier incorrectly represented by Wireshark. (Bug 11053)
- "Follow UDP Stream" on mpeg packets crashes wireshark v.1.12.4 (works fine on v.1.10.13). (Bug 11055)
- Annoying popup when trying to capture on bonds. (Bug 11058)
- Request-response cross-reference in USB URB packets incorrect. (Bug 11072)
- Right clicking in Expert Infos to create a filter (duplicate IP) results in invalid filters. (Bug 11073)
- CanOpen dissector fails on frames with RTR and 0 length. (Bug 11083)
- Typo in secp521r1 curve wrongly identified as sect521r1. (Bug 11106)
- packet-zbee-zcl.h: IS_ANALOG_SUBTYPE doesn’t filter ENUM. (Bug 11120)
- Typo: "LTE Positioning Protocol" abbreviated as "LPP", not "LLP". (Bug 11141)
- Missing Makefile.nmake in ansi1/Kerberos directory. (Bug 11155)
- Can’t build tshark without the Qt packages installed unless --without-qt is specified. (Bug 11157) Updated Protocol Support:
- AllJoyn, ASN.1 PER, ATM, CANopen, Diameter, ForCES, GSM RLC/MAC, GSMTAP, ICMP, IEC-60870-5-104, IEEE 802.11, IMF, IP, LBMC, LBMR, LDAP, LPP, MBIM, MEGACO, MP2T, PKCS-1, PPP IPv6CP, RPC, SPNEGO, SRVLOC, SSL, T.38, TCP, USB, WCP, WebSocket, X11, and ZigBee ZCL
更新時間:2015-03-05
更新細節:
What's new in this version:
The following vulnerabilities have been fixed:
- The ATN-CPDLC dissector could crash. (Bug 9952) CVE-2015-2187
- The WCP dissector could crash. (Bug 10844) CVE-2015-2188
- The pcapng file parser could crash. (Bug 10895) CVE-2015-2189
- The LLDP dissector could crash. (Bug 10983) CVE-2015-2190
- The TNEF dissector could go into an infinite loop. (Bug 11023) CVE-2015-2191
- The SCSI OSD dissector could go into an infinite loop. (Bug 11024) CVE-2015-2192
The following bugs have been fixed:
- RTP player crashes on decode of long call: BadAlloc (insufficient resources for operation). (Bug 2630)
- "Telephony→SCTP→Analyse This Association" crashes Wireshark on manufactured SCTP packet. (Bug 9849)
- IPv6 Mobility Header Link Layer Address is parsed incorrectly. (Bug 10006)
- DNS NXT RR is parsed incorrectly. (Bug 10615)
- IPv6 AUTH mobility option parses Mobility SPI and Authentication Data incorrectly. (Bug 10626)
- IPv6 Mobility Header Link-Layer Address Mobility Option is parsed incorrectly. (Bug 10627)
- HTTP chunked response includes data beyond the chunked response. (Bug 10707)
- DHCP Option 125 Suboption: (1) option-len always expects 1 but specification allows for more. (Bug 10784)
- Incorrect decoding of IPv4 Interface/Neighbor Address sub-TLVs in Extended IS Reachability TLV of IS-IS. (Bug 10837)
- Little-endian OS X Bluetooth PacketLogger files aren’t handled. (Bug 10861)
- X.509 certificate serial number incorrectly interpreted as negative number. (Bug 10862)
- Malformed Packet on rsync-version with length 2. (Bug 10863)
- ZigBee epoch time is incorrectly displayed in OTA cluster. (Bug 10872)
- BGP EVPN - Route Type 4 - "Invalid length of IP Address" - "Expert Info" shows a false error. (Bug 10873)
- Bad bytes read for extended rnc id value in GTP dissector. (Bug 10877)
- "ServiceChangeReasonStr" messages are not shown in txt generated by tshark. (Bug 10879)
- Clang ASAN : AddressSanitizer: global-buffer-overflow ANSI. (Bug 10897)
- MEGACO wrong decoding on media port. (Bug 10898)
- Wrong media format. (Bug 10899)
- BSSGP Status PDU decoding fault (missing Mandatory element (0x04) BVCI for proper packet). (Bug 10903)
- DNS LOC Precision missing units. (Bug 10940)
- Packets on OpenBSD loopback decoded as raw not null. (Bug 10956)
- Display Filter Macro unable to edit. (Bug 10957)
- IPv6 Local Mobility Anchor Address mobility option code is treated incorrectly. (Bug 10961)
- SNTP server list improperly formatted in DHCPv6 packet details. (Bug 10964)
- Juniper Packet Mirror dissector expects ipv6 flow label = 0. (Bug 10976)
- NS Trace (NetScaler Trace) file format is not able to export specified packets. (Bug 10998)
Updated Protocol Support:
- ACN, ANSI IS-637-A, AppleMIDI, ATN-CPDLC, BGP, BSSGP, CMIP, DHCP, DHCPv6, DIS, DLM3, DMP, DNS, Extreme Networks, ForCES, FTAM, GMHDR, GSM A BSSMAP, GSM A-bis OML, GSM MAP, GSM RLC MAC, GTP, H.248, H.264, HTTP, IEEE 802.11, IPv6, IS-IS, ISMACryp, J1939, Juniper Jmirror, KDP, L2CAP, LDAP, LLDP, MGCP, MIP6, NBNS, NET/ROM, Netflow, Novell PKIS, PANA, PPPoE, RSL, RSYNC, RTMPT, RTP, SCSI OSD, SDP, SMB Pipe, SMPP, SYNCHROPHASOR, TETRA, TiVoConnect, TNEF, USB HID, V.52, VSS-Monitoring, X.509AF, Zebra, and ZigBee
- New and Updated Capture File Support:
- NetScaler, PacketLogger, and Pcapng
更新時間:2015-01-08
更新細節:
What's new in this version:
Bug Fixes:
- WCCP dissector could crash. (Bug 10720, Bug 10806) CVE-2015-0559, CVE-2015-0560
- The LPP dissector could crash. (Bug 10773) CVE-2015-0561
- The DEC DNA Routing Protocol dissector could crash. (Bug 10724) CVE-2015-0562
- The SMTP dissector could crash. (Bug 10823) CVE-2015-0563
- Wireshark could crash while decypting TLS/SSL sessions. CVE-2015-0564
- WebSocket dissector: empty payload causes DISSECTOR_ASSERT_NOT_REACHED. (Bug 9332)
- Wireshark crashes if Lua heuristic dissector returns true. (Bug 10233)
- Display MEP ID in decimal in OAM Y.1731 Synthetic Loss Message and Reply PDU. (Bug 10500)
- TCP Window Size incorrectly reported in Packet List. (Bug 10514)
- Status bar "creeps" to the left a few pixels every time Wireshark is opened. (Bug 10518)
- E-LMI Message type. (Bug 10531)
- SMTP decoder can dump binary data to terminal in TShark. (Bug 10536)
- PTPoE dissector gets confused by packets that include an FCS. (Bug 10611)
- IPv6 Vendor Specific Mobility Option includes the next mobility option type. (Bug 10618)
- Save PCAP to PCAPng with commentary fails. (Bug 10656)
- Display filter "frame contains bytes [2342]" causes a crash. (Bug 10690)
- Multipath TCP: checksum displayed when it’s not there. (Bug 10692)
- LTE APN-AMBR is decoded incorrectly. (Bug 10699)
- DNS NAPTR RR Replacement Length is incorrect. (Bug 10700)
- IPv6 Experimental mobility header data is interpreted as options. (Bug 10703)
- Dissector bug, protocol SPDY: tvbuff.c:610: failed assertion "tvb && tvb→initialized". (Bug 10704)
- BGP: Incorrect decoding AS numbers when mixed AS size. (Bug 10742)
- BGP update community - incorrect decoding. (Bug 10746)
- Setting a 6LoWPAN context generates a Wireshark crash. (Bug 10747)
- FC is not dissected (protocol UNKNOWN). (Bug 10751)
- Crash when displaying several times INFO column. (Bug 10755)
- Decoding of longitude value in LCSAP (3GPP TS 29.171) is incorrect. (Bug 10767)
- Crash when enabling FCoIB manual settings without filling address field. (Bug 10796)
- RSVP RECORD_ROUTE IPv4 Subobject Flags field incorrect decoding. (Bug 10799)
- Wireshark Lua engine can’t access protocol field type. (Bug 10801)
- Field Analysis of OpenFlow v1.4 OFPT_SET_ASYNC. (Bug 10808)
- Lua: getting fieldinfo.value for FT_NONE causes assert. (Bug 10815) Updated Protocol Support:
- 6LoWPAN, ADwin, AllJoyn, Art-Net, Asterix, BGP, Bitcoin, Bluetooth OBEX, Bluetooth SDP, CFM, CIP, DCERPC PN-IO, DCERPC SPOOLSS, DEC DNA, DECT, DHCPv6, DNS, DTN, E-LMI, ENIP, Ethernet, Extreme, FCoIB, Fibre Channel, GED125, GTP, H.248, H.264, HiSLIP, IDRP, IEEE 802.11, IEEE P1722.1, Infiniband, IrDA, iSCSI, ISUP, LBMR, LCSAP, LPP, MAC LTE, MAUSB, MBIM, MIM, MIP, MIPv6, MP2T, MPEG-1, NAS EPS, NAT-PMP, NCP, NXP PN532, OpcUa, OpenFlow, PTP, RDM, RPKI-RTR, RSVP, RTnet, RTSP, SCTP, SMPP, SMTP, SPDY, Spice, TCP, WCCP, Wi-Fi P2P, and WiMAX
更新時間:2014-11-13
更新細節:
What's new in this version:
The following vulnerabilities have been fixed:
- SigComp UDVM buffer overflow.
- AMQP crash.
- NCP crashes.
- TN5250 infinite loops. The following bugs have been fixed:
- Wireshark determine packets of MMS protocol as a packets of T.125 protocol.
- 6LoWPAN Mesh headers not treated as encapsulating address.
- UCP dissector bug of operation 31 - PID 0639 not recognized.
- iSCSI dissector rejects PDUs with "expected data transfer length" > 16M.
- GTPv2: trigging_tree under Trace information has wrong length.
- openflow_v1 OFPT_FEATURES_REPLY parsed incorrectly.
- Capture files from a remote virtual interface on MacOS X 10.9.5 aren’t dissected correctly.
- Problem specifying protocol name for filtering.
- LLDP TIA Network Policy Unknown Policy Flag Decode is not correct.
- Decryption of DCERPC with Kerberos encryption fails.
- Dissection of DECRPC NT sid28 shouldn’t show expert info if tree is null.
- Attempt to render an SMS-DELIVER-REPORT instead of an SMS-DELIVER.
- IPv6 Calipso option length is not used properly.
- The SPDY dissector couldn’t dissecting packet correctly.
- IPv6 QuickStart option Nonce is read incorrectly.
- IPv6 Mobility Option IPv6 Address/Prefix marks too many bytes for the address/prefix field.
- IPv6 Mobility Option Binding Authorization Data for FMIPv6 Authenticator field is read beyond the option data.
- IPv6 Mobility Option Mobile Node Link Layer Identifier Link-layer Identifier field is read beyond the option data.
- Wrong offset for hf_mq_id_icf1 in packet-mq.c.
- Malformed PTPoE announce packet.
- IPv6 Permanent Home Keygen Token mobility option includes too many bytes for the token field.
- IPv6 Redirect Mobility Option K and N bits are parsed incorrectly.
- IPv6 Care Of Test mobility option includes too many bytes for the Keygen Token field.
- IPv6 MESG-ID mobility option is parsed incorrectly.
- IPv6 AUTH mobility option parses Mobility SPI and Authentication Data incorrectly.
- IPv6 DNS-UPDATE-TYPE mobility option includes too many bytes for the MD identity field.
- IPv6 Local Mobility Anchor Address mobility option’s code and reserved fields are parsed as 2 bytes instead of 1.
- WCCP v.2.01 extended assignment data element parsed wrong.
- DNS ISDN RR Sub Address field is read one byte early.
- TShark crashes when running with PDML on a specific packet.
- DNS A6 Address Suffix field is parsed incorrectly.
- DNS response time: calculation incorrect.
- SMPP does not display properly the hour field in the Submit_sm Validity Period field.
- DNS Name Length for Zone RR on root is 6 and Label Count is 1.
- DNS WKS RR Protocol field is read as 4 bytes instead of 1.
- IPv6 Mobility Option Context Request reads an extra request. Updated Protocol Support:
- 6LoWPAN, AMQP, ANSI IS-637-A, Bluetooth HCI, CoAP, DCERPC (all), DCERPC NT, DNS, GSM MAP, GTPv2, H.223, HPSW, HTTP2, IEEE 802.11, IPv6, iSCSI, Kerberos, LBT-RM, LLDP, MIH, Mobile IPv6, MQ, NCP, OpcUa, OpenFlow, PKTAP, PTPoE, SigComp, SMB2, SMPP, SPDY, Stanag 4607, T.125, UCP, USB CCID, and WCCP
New and Updated Capture File Support:
- Catapult DCT2000, HP-UX nettl, Ixia IxVeriWave, pcap, pcap-ng, RADCOM, and Sniffer (DOS)
更新時間:2014-09-17
更新細節:
What's new in this version:
BUG FIXES:
The following vulnerabilities have been fixed:
- wnpa-sec-2014-13: MEGACO dissector infinite loop. (Bug 10333) CVE-2014-6423
- wnpa-sec-2014-14: Netflow dissector crash. (Bug 10370) CVE-2014-6424
- wnpa-sec-2014-15: CUPS dissector crash. (Bug 10353) CVE-2014-6425
- wnpa-sec-2014-16: HIP dissector infinite loop. CVE-2014-6426
- wnpa-sec-2014-17: RTSP dissector crash. (Bug 10381) CVE-2014-6427
- wnpa-sec-2014-18: SES dissector crash. (Bug 10454) CVE-2014-6428
- wnpa-sec-2014-19: Sniffer file parser crash. (Bug 10461) CVE-2014-6429 CVE-2014-6430 CVE-2014-6431 CVE-2014-6432 The following bugs have been fixed:
- Wireshark can crash during remote capture (rpcap) configuration. (Bug 3554, Bug 6922, ws-buglink:7021)
- 802.11 capture does not decrypt/decode DHCP response. (Bug 8734)
- Extra quotes around date fields (FT_ABSOLUTE_TIME) when using -E quote=d or s. (Bug 10213)
- No progress line in "VOIP RTP Player". (Bug 10307)
- MIPv6 Service Selection Identifier parse error. (Bug 10323)
- Probably wrong length check in proto_item_set_end. (Bug 10329)
- 802.11 BA sequence number decode is broken. (Bug 10334)
- wmem_alloc_array() "succeeds" (and clobbers memory) when requested to allocate 0xaaaaaaaa items of size 12. (Bug 10343)
- Different dissection results for same file. (Bug 10348)
- Mergecap wildcard breaks in version 1.12.0. (Bug 10354)
- Diameter TCP reassemble. (Bug 10362)
- TRILL NLPID 0xc0 unknown to Wireshark. (Bug 10382)
- BTLE advertising header flags (RxAdd/TxAdd) dissected incorrectly. (Bug 10384)
- Ethernet OAM (CFM) frames including TLV’s are wrongly decoded as malformed. (Bug 10385)
- BGP4: Wireshark skipped some potion of AS_PATH. (Bug 10399)
- MAC address name resolution is broken. (Bug 10344)
- Wrong decoding of RPKI RTR End of Data PDU. (Bug 10411)
- SSL/TLS dissector incorrectly interprets length for status_request_v2 hello extension. (Bug 10416)
- Misparsed NTP control assignments with empty values. (Bug 10417)
- 6LoWPAN multicast address decompression problems. (Bug 10426)
- Netflow v9 flowset not decoded if options template has zero-length scope section. (Bug 10432)
- GUI Hangs when Selecting Path to GeoIP Files. (Bug 10434)
- AX.25 dissector prints unprintable characters. (Bug 10439)
- 6LoWPAN context handling not working. (Bug 10443)
- SIP: When export to a CSV, Info is changed to differ. (Bug 10453)
- Typo in packet-netflow.c. (Bug 10458)
- Incorrect MPEG-TS decoding (OPCR field). (Bug 10446) UPDATED PROTOCOL SUPPORT:
- 6LoWPAN, A21, ACR122, Art-Net, AX.25, BGP, BTLE, CAPWAP, DIAMETER, DICOM, DVB-CI, Ethernet OAM, HIP, HiSLIP, HTTP2, IEEE 802.11, MAUSB, MEGACO, MIPv6, MP2T, Netflow, NTP, openSAFETY, OSI, RDM, RPKI RTR, RTSP, SES, SIP, TLS, and Token Ring MAC NEW AND UPDATED CAPTURE FILE SUPPORT:
- DOS Sniffer and NetScaler
更新時間:2014-08-01
更新細節:
What's new in this version:
Bug Fixes:
- "On-the-wire" packet lengths are limited to 65535 bytes. (Bug 8808, Bug 9390)
- "Follow TCP Stream" shows only the first HTTP request and response. (Bug 9044)
- Files with pcap-ng Simple Packet Blocks can’t be read. (Bug 9200)
- MPLS-over-PPP isn’t recognized. (Bug 9492) New and updated features:
- The Windows installer now uninstalls the previous version of Wireshark silently. You can still run the uninstaller manually beforehand if you wish to run it interactively.
- Expert information is now filterable when the new API is in use.
- The "Number" column shows related packets and protocol conversation spans (Qt only).
- When manipulating packets with editcap using the -C and/or -s options, it is now possible to also adjust the original frame length using the -L option.
- You can now pass the -C option to editcap multiple times, which allows you to chop bytes from the beginning of a packet as well as at the end of a packet in a single step.
- You can now specify an optional offset to the -C option for editcap, which allows you to start chopping from that offset instead of from the absolute packet beginning or end.
"malformed" display filter has been renamed to "_ws.malformed". A handful of other filters have been given the "_ws." prefix to note they are Wireshark application specific filters and not dissector filters.
- The Kerberos dissector has been replaced with an auto generated one from ASN1 protocol description, changing a lot of filter names.
- Additionally the Windows installers have an extra component: a preview of the upcoming user interface for Wireshark 2.0.
- The following features are new (or have been significantly updated) since version 1.11.3:
- Transport name resolution is now disabled by default.
- Support has been added for all versions of the DCBx protocol.
- Cleanup of LLDP code, all dissected fields are now navigable. The following features are new (or have been significantly updated) since version 1.11.2: Qt port:
- The About dialog has been added
- The Capture Interfaces dialog has been added.
- The Decode As dialog has been added. It managed to swallow up the User Specified Decodes dialog as well.
- The Export PDU dialog has been added.
- Several SCTP dialogs have been added.
- The statistics tree (the backend for many Statistics and Telephony menu items) dialog has been added.
- The I/O Graph dialog has been added.
- French translation has updated. The following features are new (or have been significantly updated) since version 1.11.0:
- Dissector output may be encoded as UTF-8. This includes TShark output. Qt port:
- The Follow Stream dialog now supports packet and TCP stream selection.
- A Flow Graph (sequence diagram) dialog has been added.
- The main window now respects geometry preferences. Removed Dissectors:
- The ASN1 plugin has been removed as it’s deemed obsolete.
- The GNM dissector has been removed as it was never used.
- The Kerberos hand made dissector has been replaced by one generated from ASN1 code. Platform Support:
- Support for Windows XP has been deprecated. We will make an effort to support it for as long as possible but our ability to do so depends on upstream packages and other factors beyond our control.
- U3 packages are no longer supported or provided. New protocol support:
- 29West, 802.1AE Secure tag, A21, ACR122, ADB Client-Server, AllJoyn, Apple PKTAP, Aruba Instant AP, ASTERIX, ATN, Bencode, Bluetooth 3DS, Bluetooth HSP, Bluetooth Linux Monitor Transport, Bluetooth Low Energy, Bluetooth Low Energy RF Info, CARP, CFDP, Cisco MetaData, DCE/RPC MDSSVC, DeviceNet, ELF file format, Ethernet Local Management Interface (E-LMI), Ethernet Passive Optical Network (EPON), EXPORTED PDU, FINGER, HDMI, High-Speed LAN Instrument Protocol (HiSLIP), HTTP2, IDRP, IEEE 1722a, ILP, iWARP Direct Data Placement and Remote Direct Memory Access Protocol, Kafka, Kyoto Tycoon, Landis & Gyr Telegyr 8979, LBM, LBMC, LBMPDM, LBMPDM-TCP, LBMR, LBT-RM, LBT-RU, LBT-TCP, Lightweight Mesh (v1.1.1), Link16, Linux netlink, Linux netlink netfilter, Linux netlink sock diag, Linux rtnetlink (route netlink), Logcat, MBIM, Media Agnostic USB (MA USB), MiNT, MP4 / ISOBMFF file format, MQ Telemetry Transport Protocol, MS NLB (Rewrite), Novell PKIS certificate extensions, NXP PN532 HCI, Open Sound Control, OpenFlow, Pathport, PDC, Picture Transfer Protocol Over IP, PKTAP, Private Data Channel, QUIC (Quick UDP Internet Connections), SAE J1939, SEL RTAC (Real Time Automation Controller) EIA-232 Serial-Line Dissection, Sippy RTPproxy, SMB-Direct, SPDY, STANAG 4607, STANAG 5066 DTS, STANAG 5066 SIS, Tinkerforge, Ubertooth, UDT, URL Encoded Form Data, USB Communications and CDC Control, USB Device Firmware Upgrade, VP8, WHOIS, Wi-Fi Display, and ZigBee Green Power profile New and updated capture file support:
- Netscaler 2.6, STANAG 4607, and STANAG 5066 Data Transfer Sublayer Major API changes:
- A more flexible, modular memory manager (wmem) has been added. It was available experimentally in 1.10 but is now mature and has mostly replaced the old emem API (which is deprecated).
- A new API for expert information has been added, replacing the old one.
- The tvbuff API has been cleaned up: tvb_length has been renamed to tvb_captured_length for clarity, and tvb_get_string and tvb_get_stringz have been deprecated in favour of tvb_get_string_enc and tvb_get_stringz_enc.
- dissector_try_heuristic() signature has been changed to return heur_dtbl_entry_t to make it possible to save it and use it in subsequent calls to avoid the overhead of going trough the heuristics list.
更新時間:2014-06-13
更新細節:
What's new in this version:
- The following vulnerabilities have been fixed.
- wnpa-sec-2014-07 - The frame metadissector could crash.
The following bugs have been fixed:
- VoIP flow graph crash upon opening.
- Tshark with "-F pcap" still generates a pcapng file.
- IPv6 Next Header 0x3d recognized as SHIM6.
- Failed to export pdml on large pcap.
- TCAP: set a fence on info column after calling sub dissector
- Dissector bug in JSON protocol.
- GSM RLC MAC: do not skip too many lines of the CSN_DESCR when the field is missing
- Wireshark PEEKREMOTE incorrectly decoding QoS data packets from Cisco Sniffer APs.
- IEEE 802.11: fix dissection of HT Capabilities
Updated Protocol Support:
- CIP, EtherNet/IP, GSM RLC MAC, IEEE 802.11, IPv6, and TCAP
- New and Updated Capture File Support:
- pcap-ng, and PEEKREMOTE
更新時間:2014-04-23
更新細節:
What's new in this version:
The following vulnerabilities have been fixed:
- wnpa-sec-2014-06: The RTP dissector could crash. (Bug 9885). Versions affected: 1.10.0 to 1.10.6. CVE-2014-2907
The following bugs have been fixed:
- RTP not decoded inside the conversation in v.1.10.1 (Bug 9021)
- SIP/SDP: disabled second media stream disables all media streams (Bug 9835)
- Lua: trying to get/access a Preference before its registered causes a segfault (Bug 9853)
- Some value_string strings contain newlines. (Bug 9878)
- Tighten the NO_MORE_DATA_CHECK macros (Bug 9932)
- Fix crash when calling "MAP Summary" dialog when no file is open (Bug 9934)
- Fix comparing a sequence number of TCP fragment when its value wraps over uint32_t limit (Bug 9936)
Updated Protocol Support:
- ANSI A, DVB-CI, GSM DTAP, GSM MAP, IEEE 802.11, LCSAP, LTE RRC, MAC LTE, Prism, RTP, SDP, SIP, and TCP
更新時間:2014-03-09
更新細節:
What's new in this version:
Bug Fixes: The following vulnerabilities have been fixed:
- wnpa-sec-2014-01
- The NFS dissector could crash.
- Versions affected: 1.10.0 to 1.10.5, 1.8.0 to 1.8.12
- CVE-2014-2281
- wnpa-sec-2014-02
- The M3UA dissector could crash.
- Versions affected: 1.10.0 to 1.10.5
- CVE-2014-2282
- wnpa-sec-2014-03
- The RLC dissector could crash. (Bug 9730)
- Versions affected: 1.10.0 to 1.10.5, 1.8.0 to 1.8.12
- CVE-2014-2283
- wnpa-sec-2014-04
- The MPEG file parser could overflow a buffer.
- Versions affected: 1.10.0 to 1.10.5, 1.8.0 to 1.8.12
- CVE-2014-2299 The following bugs have been fixed:
- Customized OUI is not recognized correctly during dissection. (Bug 9122)
- Properly decode CAPWAP Data Keep-Alives. (Bug 9165)
- Build failure with GTK 3.10 - GTK developers have gone insane. (Bug 9340)
- SIGSEGV/SIGABRT during free of TvbRange using a chained dissector in lua. (Bug 9483)
- MPLS dissector no longer registers itself in "ppp.protocol" table. (Bug 9492)
- Tshark doesn’t display the longer data fields (mbtcp). (Bug 9572)
- DMX-CHAN disector does not clear strbuf between rows. (Bug 9598)
- Dissector bug, protocol SDP: proto.c:4214: failed assertion "length >= 0". (Bug 9633)
- False error: capture file appears to be damaged or corrupt. (Bug 9634)
- SMPP field source_telematics_id field length different from spec. (Bug 9649)
- Lua: bitop library is missing in Lua 5.2. (Bug 9720)
- GTPv1-C / MM Context / Authentication quintuplet / RAND is not correct. (Bug 9722)
- Lua: ProtoField.new() is buggy. (Bug 9725)
- Lua: ProtoField.bool() VALUESTRING argument is not optional but was supposed to be. (Bug 9728)
- Problem with CAPWAP Wireshark Dissector. (Bug 9752)
- nas-eps dissector: CS Service notification dissection stops after Paging identity IE. (Bug 9789) New and Updated Features:
- IPv4 checksum verfification is now disabled by default. Updated Protocol Support:
- AppleTalk, CAPWAP, DMX-CHAN, DSI, DVB-CI, ESS, GTPv1, IEEE 802a, M3UA, Modbus/TCP, NAS-EPS, NFS, OpenSafety, SDP, and SMPP New and Updated Capture File Support:
- libpcap, MPEG, and pcap-ng
更新時間:2013-12-21
更新細節:
What's new in this version:
The following bugs have been fixed:
- Wireshark stops showing new packets but dumpcap keeps writing them to the temp file. (Bug 9571)
- Wireshark 1.10.4 shuts down when promiscuous mode is unchecked. (Bug 9577)
- Homeplug dissector bug: STATUS_ACCESS_VIOLATION: dissector accessed an invalid memory address. (Bug 9578)
New and Updated Features:
- There are no new features in this release.
New Protocol Support:
- There are no new protocols in this release.
Updated Protocol Support:
- GSM BSSMAP, GSM BSSMAP LE, GSM SMS, Homeplug, NAS-EPS, and SGSAP
New and Updated Capture File Support:
- There is no updated capture file support in this release