= Wireshark wireshark-version:[] Release Notes == What is Wireshark? Wireshark is the world's most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. == What's New === Bug Fixes // Link templates: ws-buglink:5000[] ws-buglink:6000[Wireshark bug] cve-idlink:2013-2486[] The following vulnerabilities have been fixed. * ws-salink:2015-30[] + Pcapng file parser crash. Discovered by Dario Lombardo and Shannon Sabens. // Fixed in master: g7249791 // Fixed in master-1.12: g21ec666 (ws-buglink:11455[]) //cve-idlink:2015-XXXX[] The following bugs have been fixed: //* Wireshark always manages to score tickets for Burning Man, Coachella, and // SXSW while you end up working double shifts. (ws-buglink:0000[]) // cp /dev/null /tmp/buglist.txt ; for bugnumber in `git log --stat v1.12.9rc0..| grep ' Bug:' | cut -f2 -d: | sort -n -u ` ; do gen-bugnote $bugnumber; pbpaste >> /tmp/buglist.txt; done * Last Address field for IPv6 RPL routing header is interpreted incorrectly. (ws-buglink:10560[]) * Comparing two capture files crashes Wireshark when navigating the results. (ws-buglink:11098[]) * 802.11 frame is not correctly dissected if it contains HT Control. (ws-buglink:11351[]) * GVCP bit-fields not updated. (ws-buglink:11442[]) * Tshark crash when specifying ssl.keys_list on CLI. (ws-buglink:11443[]) * pcapng: SPB capture length is incorrectly truncated if IDB snaplen = 0. (ws-buglink:11483[]) * pcapng: NRB IPv4 address is endian swapped but shouldn't be. (ws-buglink:11484[]) * pcapng: NRB with options causes file read failure. (ws-buglink:11485[]) * pcapng: ISB without if_drop option is shown as max value. (ws-buglink:11489[]) * UNISTIM dissector - Message length not included in offset for "Select Adjustable Rx Volume". (ws-buglink:11497[]) === New and Updated Features There are no new features in this release. === New Protocol Support There are no new protocols in this release. === Updated Protocol Support --sort-and-group-- DIAMETER GVCP IEEE 802.11 IPv6 UNISTIM --sort-and-group-- === New and Updated Capture File Support //There is no new or updated capture file support in this release. --sort-and-group-- pcapng --sort-and-group-- == Getting Wireshark Wireshark source code and installation packages are available from https://www.wireshark.org/download.html. === Vendor-supplied Packages Most Linux and Unix vendors supply their own Wireshark packages. You can usually install or upgrade Wireshark using the package management system specific to that platform. A list of third-party packages can be found on the https://www.wireshark.org/download.html#thirdparty[download page] on the Wireshark web site. == File Locations Wireshark and TShark look in several different locations for preference files, plugins, SNMP MIBS, and RADIUS dictionaries. These locations vary from platform to platform. You can use About→Folders to find the default locations on your system. == Known Problems Dumpcap might not quit if Wireshark or TShark crashes. (ws-buglink:1419[]) The BER dissector might infinitely loop. (ws-buglink:1516[]) Capture filters aren't applied when capturing from named pipes. (ws-buglink:1814[]) Filtering tshark captures with read filters (-R) no longer works. (ws-buglink:2234[]) The 64-bit Windows installer does not support Kerberos decryption. (https://wiki.wireshark.org/Development/Win64[Win64 development page]) Resolving (ws-buglink:9044[]) reopens (ws-buglink:3528[]) so that Wireshark no longer automatically decodes gzip data when following a TCP stream. Application crash when changing real-time option. (ws-buglink:4035[]) Hex pane display issue after startup. (ws-buglink:4056[]) Packet list rows are oversized. (ws-buglink:4357[]) Wireshark and TShark will display incorrect delta times in some cases. (ws-buglink:4985[]) == Getting Help Community support is available on https://ask.wireshark.org/[Wireshark's Q&A site] and on the wireshark-users mailing list. Subscription information and archives for all of Wireshark's mailing lists can be found on https://www.wireshark.org/lists/[the web site]. Official Wireshark training and certification are available from http://www.wiresharktraining.com/[Wireshark University]. == Frequently Asked Questions A complete FAQ is available on the https://www.wireshark.org/faq.html[Wireshark web site].