What's New in version 1.4.3:
- AMQP failed assertion. (Bug 4048)
- Reassemble.c leaks memory for GLIB > 2.8. (Bug 4141)
- Fuzz testing reports possible dissector bug: TCP. (Bug 4211)
- Wrong length calculation in new_octet_aligned_subset_bits() (PER dissector). (Bug 5393)
- Function dissect_per_bit_string_display might read more bytes than available (PER dissector). (Bug 5394)
- Cannot load wpcap.dll & packet.dll from Wireshark program directory. (Bug 5420)
- Wireshark crashes with Copy -> Description on date/time fields. (Bug 5421)
- DHCPv6 OPTION_CLIENT_FQDN parse error. (Bug 5426)
- Information element Error for supported channels. (Bug 5430)
- Assert when using ASN.1 dissector with loading a 'type table'. (Bug 5447)
- Bug with RWH parsing in Infiniband dissector. (Bug 5444)
- Help->About Wireshark mis-reports OS. (Bug 5453)
- Delegated-IPv6-Prefix(123) is shown incorrect as X-Ascend-Call-Attempt-Limit(123). (Bug 5455)
- "tshark -r file -T fields" is truncating exported data. (Bug 5463)
- gsm_a_dtap: incorrect "Extraneous Data" when decoding Packet Flow Identifier. (Bug 5475)
- Improper decode of TLS 1.2 packet containing both CertificateRequest and ServerHelloDone messages. (Bug 5485)
- LTE-PDCP UL and DL problem. (Bug 5505)
- CIGI 3.2/3.3 support broken. (Bug 5510)
- Prepare Filter in RTP Streams dialog does not work correctly. (Bug 5513)
- Wrong decode at ethernet OAM Y.1731 ETH-CC. (Bug 5517)
- WPS: RF bands decryption. (Bug 5523)
- Incorrect LTP SDNV value handling. (Bug 5521)
- LTP bug found by randpkt. (Bug 5323)
- Buffer overflow in SNMP EngineID preferences. (Bug 5530)
Updated Protocol Support:
- AMQP, ASN.1 BER, ASN.1 PER, CFM, CIGI, DHCPv6, Diameter, ENTTEC, GSM A GM, IEEE 802.11, InfiniBand, LTE-PDCP, LTP, MAC-LTE, MP2T, RADIUS, SAMR, SCCP, SIP, SNMP, TCP, TLS, TN3270, UNISTIM, WPS
New and Updated Capture File Support:
- Endace ERF, Microsoft Network Monitor, VMS TCPtrace.
What's New in version 1.4.2:
Bug Fixes:
- File-Open Display Filter is overwritten by Save-As Filename. (Bug 3894)
- Wireshark crashes with "Gtk-ERROR **: Byte index 6 is off the end of the line" if click on last PDU. (Bug 5285)
- GTK-ERROR can occur in packets when there are multiple Netbios/SMB headers in a single frame. (Bug 5289)
- "Tshark -G values" crashes on Windows. (Bug 5296)
- PROFINET I&M0FilterData packet not fully decoded. (Bug 5299)
- PROFINET MRP linkup/linkdown decoding incorrect. (Bug 5300)
- [lua] Dumper:close() will cause a segfault due later GC of the Dumper. (Bug 5320)
- Network Instruments' trace files sometimes cannot be read with an error message of "Observer: bad record: Invalid magic number". (Bug 5330)
- IO Graph Time of Day times incorrect for filtered data. (Bug 5340)
- Wireshark tools do not detect and read some ERF files correctly. (Bug 5344)
- "editcap -h" sends some lines to stderr and others to stdout. (Bug 5353)
- IP Timestamp Option: "flag=3" variant (prespecified) not displayed correctly. (Bug 5357)
- AgentX PDU Header 'hex field highlighting' incorrectly spans extra bytes. (Bug 5364)
- AgentX dissector cannot handle null OID in Open-PDU. (Bug 5368)
- Crash with "Gtk-ERROR **: Byte index 6 is off the end of the line". (Bug 5374)
- ANCP Portmanagment TLV wrong decoded. (Bug 5388)
- Crash during startup because of Python SyntaxError in wspy_libws.py. (Bug 5389)
What's New in version 1.4.1:
Bug Fixes:
- The Penetration Test Team of NCNIPC (China) discovered that the ASN.1 BER dissector was susceptible to a stack overflow. (Bug 5230) Versions affected: All previous versions up to and including 1.2.11 and 1.4.0.
- Wireshark may appear offscreen on multi-monitor Windows systems. (Bug 553)
- Incorrect behavior using sorting in the packet list. (Bug 2225)
- Cooked-capture dissector should omit the source address field if empty. (Bug 2519)
- MySQL dissector doesn't dissect MySQL stream. (Bug 2691)
- Wireshark crashes if active display filter macro is renamed. (Bug 5002)
- Incorrect dissection of MAP V2 PRN_ACK. (Bug 5076)
- TCP bytes_in_flight becomes inflated with lost packets. (Bug 5132)
- Wireshark fails to start on Windows XP 64bit. (Bug 5160)
- GTP header is exported in PDML with an incorrect size. (Bug 5162)
- Packet list hidden columns will not be parsed correctly from preferences file. (Bug 5163)
- Wireshark does not display the t.38 graph. (Bug 5165)
- Wireshark don't show mgcp calls in "Telephony ? VoIP calls". (Bug 5167)
- Wireshark 1.4.0 & VoIP calls "Prepare Filter" problem. (Bug 5172)
- GTPv2: IMSI is decoded improperly. (Bug 5179)
- [NAS EPS] EPS Quality of Service IE decoding is wrong. (Bug 5186)
- Wireshark mistakenly writes "not all data available" for IPv4 checksum. (Bug 5194)
- GSM: Cell Channel Description, range 1024 format. (Bug 5214)
- Wrong SDP interpretation on VoIP call flow chart. (Bug 5220)
- The CLDAP attribute value on a CLDAP reply is no longer being decoded. (Bug 5239)
- [NAS EPS] Traffic Flow Template IE dissection bugs. (Bug 5243)
- [NAS EPS] Use Request Type IE defined in 3GPP 24.008. (Bug 5246)
- NTLMSSP_AUTH domain and username truncated to first letter with IE8/Windows7 (generating the NTLM packet). (Bug 5251)
- IPv6 RH0: dest addr is to be used i.s.o. last RH address when 0 segments remain. (Bug 5252)
- EIGRP dissection error in Flags field in external route TLVs. (Bug 5261)
- MRP packet is not correctly parsed in PROFINET multiple write record request. (Bug 5267)
- MySQL Enhancement: support of Show Fields and bug fix. (Bug 5271)
- [NAS EPS] Fix TFT decoding when having several Packet Filters defined. (Bug 5274)
- Crash if using ssl.debug.file with no password for ssl.keys_list. (Bug 5277) ne option.
- You can open JPEG files directly in Wireshark.
What's New in version 1.4.0:
Bug Fixes:
- Update time display in background. (Bug 1275)
- Wireshark is unresponsive when capturing from named pipes on Windows. (Bug 1759)
- Tshark returns 0 even with an invalid interface or capture filter. (Bug 4735)
New and Updated Features:
- The packet list internals have been rewritten and are now more efficient.
- Columns are easier to use. You can add a protocol field as a column by right-clicking on its packet detail item, and you can adjust some column preferences by right-clicking the column header.
- Preliminary Python scripting support has been added.
- Many memory leaks have been fixed.
- Wireshark 1.4 does not support Windows 2000. Please use Wireshark 1.2 or 1.0 on those systems.
- Packets can now be ignored (excluded from dissection), similar to the way they can be marked.
- Manual IP address resolution is now supported.
- Columns with seconds can now be displayed as hours, minutes and seconds.
- You can now set the capture buffer size on UNIX and Linux if you have libpcap 1.0.0 or greater.
- TShark no longer needs elevated privileges on UNIX or Linux to list interfaces. Only dumpcap requires privileges now.
- Wireshark and TShark can enable 802.11 monitor mode directly if you have libpcap 1.0.0 or greater.
- You can play RTP streams directly from the RTP Analysis window.
- Capinfos and editcap now respectively support time order checking and forcing.
- Wireshark now has a "jump to timestamp" command-line option.
- You can open JPEG files directly in Wireshark.
|