Wireshark Version 4.4.9
Network protocol analyzer
Wireshark EXE x64 Version 4.4.9
Wireshark 4.4.9 Release Notes$$$What’s New$$$Bug Fixes$$$wnpa-sec-2025-03 SSH dissector crash. Issue 20642.$$$$$$The following bugs have been fixed:$$$$$$RDM Product Detail List ID Disect incorrect. Issue 20612.$$$$$$SCCP LUDT segmentation decoding fails. Issue 20647.$$$$$$Ciscodump fails to start capture on Cisco IOS. Issue 20655.$$$$$$[BACnet] WritePropertyMultiple closing context tag 1 not showing. Issue 20665.$$$$$$Bug in LZ77 decoder; reads a 16-bit length when it should read a 32-bit length. Issue 20671.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$BACapp; LIN; MySQL; RDM; SABP; SCCP; sFlow; and SSH$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.
Wireshark MSI x64 Version 4.4.9.0
Wireshark 4.4.9 Release Notes$$$What’s New$$$Bug Fixes$$$wnpa-sec-2025-03 SSH dissector crash. Issue 20642.$$$$$$The following bugs have been fixed:$$$$$$RDM Product Detail List ID Disect incorrect. Issue 20612.$$$$$$SCCP LUDT segmentation decoding fails. Issue 20647.$$$$$$Ciscodump fails to start capture on Cisco IOS. Issue 20655.$$$$$$[BACnet] WritePropertyMultiple closing context tag 1 not showing. Issue 20665.$$$$$$Bug in LZ77 decoder; reads a 16-bit length when it should read a 32-bit length. Issue 20671.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$BACapp; LIN; MySQL; RDM; SABP; SCCP; sFlow; and SSH$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark Version 4.4.8
Network protocol analyzer
Wireshark MSI x64 Version 4.4.8.0
What’s New$$$Bug Fixes$$$The following bugs have been fixed:$$$$$$Renegotiated DTLS session is not being decrypted. Issue 20362.$$$$$$Wireshark is completely stuck in initialization because androiddump recv() is blocked. Issue 20526.$$$$$$Fuzz job UTF-8 encoding issue: fuzz-2025-06-20-7318.pcap. Issue 20585.$$$$$$Crash when showing packet in new window after reloading Lua plugins with a certain gui.column.format preference. Issue 20588.$$$$$$Bug in UDS dissector with Service ReadDataByPeriodicIdentifier Response. Issue 20589.$$$$$$Packet diagram doesn’t show non-standard field value representations. Issue 20590.$$$$$$Packet diagram shows representation twice when field type is FT_NONE. Issue 20601.$$$$$$application/x-www-form-urlencoded key parsed incorrectly following a name-value byte sequence with no = Issue 20615.$$$$$$DNP3 time stamp was unable to work after epoch time(year 2038) Issue 20618.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$ASTERIX; DLT; DNP 3.0; DOF; DTLS; ETSI CAT; Gryphon; IPsec; ISObus VT; KRB5; MBIM; RTCP; SLL; STCSIG; TETRA; UDS; and URL Encoded Form Data$$$$$$New and Updated Capture File Support$$$pcapng$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark EXE x64 Version 4.4.8
Wireshark 4.4.8 Release Notes$$$What’s New$$$Bug Fixes$$$The following bugs have been fixed:$$$$$$Renegotiated DTLS session is not being decrypted. Issue 20362.$$$$$$Wireshark is completely stuck in initialization because androiddump recv() is blocked. Issue 20526.$$$$$$Fuzz job UTF-8 encoding issue: fuzz-2025-06-20-7318.pcap. Issue 20585.$$$$$$Crash when showing packet in new window after reloading Lua plugins with a certain gui.column.format preference. Issue 20588.$$$$$$Bug in UDS dissector with Service ReadDataByPeriodicIdentifier Response. Issue 20589.$$$$$$Packet diagram doesn’t show non-standard field value representations. Issue 20590.$$$$$$Packet diagram shows representation twice when field type is FT_NONE. Issue 20601.$$$$$$application/x-www-form-urlencoded key parsed incorrectly following a name-value byte sequence with no = Issue 20615.$$$$$$DNP3 time stamp was unable to work after epoch time(year 2038) Issue 20618.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$ASTERIX; DLT; DNP 3.0; DOF; DTLS; ETSI CAT; Gryphon; IPsec; ISObus VT; KRB5; MBIM; RTCP; SLL; STCSIG; TETRA; UDS; and URL Encoded Form Data$$$$$$New and Updated Capture File Support$$$pcapng$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark MSI x64 Version 4.4.8.0
What’s New$$$Bug Fixes$$$The following bugs have been fixed:$$$$$$Renegotiated DTLS session is not being decrypted. Issue 20362.$$$$$$Wireshark is completely stuck in initialization because androiddump recv() is blocked. Issue 20526.$$$$$$Fuzz job UTF-8 encoding issue: fuzz-2025-06-20-7318.pcap. Issue 20585.$$$$$$Crash when showing packet in new window after reloading Lua plugins with a certain gui.column.format preference. Issue 20588.$$$$$$Bug in UDS dissector with Service ReadDataByPeriodicIdentifier Response. Issue 20589.$$$$$$Packet diagram doesn’t show non-standard field value representations. Issue 20590.$$$$$$Packet diagram shows representation twice when field type is FT_NONE. Issue 20601.$$$$$$application/x-www-form-urlencoded key parsed incorrectly following a name-value byte sequence with no = Issue 20615.$$$$$$DNP3 time stamp was unable to work after epoch time(year 2038) Issue 20618.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$ASTERIX; DLT; DNP 3.0; DOF; DTLS; ETSI CAT; Gryphon; IPsec; ISObus VT; KRB5; MBIM; RTCP; SLL; STCSIG; TETRA; UDS; and URL Encoded Form Data$$$$$$New and Updated Capture File Support$$$pcapng$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark EXE x64 Version 4.4.8
Wireshark 4.4.8 Release Notes$$$What’s New$$$Bug Fixes$$$The following bugs have been fixed:$$$$$$Renegotiated DTLS session is not being decrypted. Issue 20362.$$$$$$Wireshark is completely stuck in initialization because androiddump recv() is blocked. Issue 20526.$$$$$$Fuzz job UTF-8 encoding issue: fuzz-2025-06-20-7318.pcap. Issue 20585.$$$$$$Crash when showing packet in new window after reloading Lua plugins with a certain gui.column.format preference. Issue 20588.$$$$$$Bug in UDS dissector with Service ReadDataByPeriodicIdentifier Response. Issue 20589.$$$$$$Packet diagram doesn’t show non-standard field value representations. Issue 20590.$$$$$$Packet diagram shows representation twice when field type is FT_NONE. Issue 20601.$$$$$$application/x-www-form-urlencoded key parsed incorrectly following a name-value byte sequence with no = Issue 20615.$$$$$$DNP3 time stamp was unable to work after epoch time(year 2038) Issue 20618.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$ASTERIX; DLT; DNP 3.0; DOF; DTLS; ETSI CAT; Gryphon; IPsec; ISObus VT; KRB5; MBIM; RTCP; SLL; STCSIG; TETRA; UDS; and URL Encoded Form Data$$$$$$New and Updated Capture File Support$$$pcapng$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark MSI x64 Version 4.4.7.0
What’s New$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2025-02 Dissection engine crash. CVE-2025-5601.$$$$$$The following bugs have been fixed:$$$$$$Wireshark does not correctly decode LIN go to sleep in TECMP and CMP. $$$$$$Dissector bug; Protocol CIGI.$$$$$$Green power packets are not dissected when proto_version == ZBEE_VERSION_GREEN_POWER.$$$$$$Packet diagrams misalign or drop bitfields. $$$$$$Corruption when setting heuristic dissector table UI name from Lua.$$$$$$LDAP dissector incorrectly displays filters with singleton &$$$$$$WebSocket per-message compression extentions: fail to decompress server messages (from the 2nd) due to parameter handling.$$$$$$The LL_PERIODIC_SYNC_WR_IND packet is not properly dissected (packet-btle.c)$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$AT; BT LE LL; CIGI; genl; LDAP; LIN; Logcat Text; net_dm; netfilter; nvme; SSH; TCPCL; TLS; WebSocket; ZigBee; and ZigBee ZCL$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark EXE x64 Version 4.4.7
What’s New$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2025-02 Dissection engine crash. CVE-2025-5601.$$$$$$The following bugs have been fixed:$$$$$$Wireshark does not correctly decode LIN go to sleep in TECMP and CMP. $$$$$$Dissector bug; Protocol CIGI.$$$$$$Green power packets are not dissected when proto_version == ZBEE_VERSION_GREEN_POWER.$$$$$$Packet diagrams misalign or drop bitfields. $$$$$$Corruption when setting heuristic dissector table UI name from Lua.$$$$$$LDAP dissector incorrectly displays filters with singleton &$$$$$$WebSocket per-message compression extentions: fail to decompress server messages (from the 2nd) due to parameter handling.$$$$$$The LL_PERIODIC_SYNC_WR_IND packet is not properly dissected (packet-btle.c)$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$AT; BT LE LL; CIGI; genl; LDAP; LIN; Logcat Text; net_dm; netfilter; nvme; SSH; TCPCL; TLS; WebSocket; ZigBee; and ZigBee ZCL$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark MSI x64 Version 4.4.7.0
What’s New$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2025-02 Dissection engine crash. CVE-2025-5601.$$$$$$The following bugs have been fixed:$$$$$$Wireshark does not correctly decode LIN go to sleep in TECMP and CMP. $$$$$$Dissector bug; Protocol CIGI.$$$$$$Green power packets are not dissected when proto_version == ZBEE_VERSION_GREEN_POWER.$$$$$$Packet diagrams misalign or drop bitfields. $$$$$$Corruption when setting heuristic dissector table UI name from Lua.$$$$$$LDAP dissector incorrectly displays filters with singleton &$$$$$$WebSocket per-message compression extentions: fail to decompress server messages (from the 2nd) due to parameter handling.$$$$$$The LL_PERIODIC_SYNC_WR_IND packet is not properly dissected (packet-btle.c)$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$AT; BT LE LL; CIGI; genl; LDAP; LIN; Logcat Text; net_dm; netfilter; nvme; SSH; TCPCL; TLS; WebSocket; ZigBee; and ZigBee ZCL$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark EXE x64 Version 4.4.7
What’s New$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2025-02 Dissection engine crash. CVE-2025-5601.$$$$$$The following bugs have been fixed:$$$$$$Wireshark does not correctly decode LIN go to sleep in TECMP and CMP. $$$$$$Dissector bug; Protocol CIGI.$$$$$$Green power packets are not dissected when proto_version == ZBEE_VERSION_GREEN_POWER.$$$$$$Packet diagrams misalign or drop bitfields. $$$$$$Corruption when setting heuristic dissector table UI name from Lua.$$$$$$LDAP dissector incorrectly displays filters with singleton &$$$$$$WebSocket per-message compression extentions: fail to decompress server messages (from the 2nd) due to parameter handling.$$$$$$The LL_PERIODIC_SYNC_WR_IND packet is not properly dissected (packet-btle.c)$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$AT; BT LE LL; CIGI; genl; LDAP; LIN; Logcat Text; net_dm; netfilter; nvme; SSH; TCPCL; TLS; WebSocket; ZigBee; and ZigBee ZCL$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark MSI x64 Version 4.4.7.0
What’s New$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2025-02 Dissection engine crash. CVE-2025-5601.$$$$$$The following bugs have been fixed:$$$$$$Wireshark does not correctly decode LIN go to sleep in TECMP and CMP. $$$$$$Dissector bug; Protocol CIGI.$$$$$$Green power packets are not dissected when proto_version == ZBEE_VERSION_GREEN_POWER.$$$$$$Packet diagrams misalign or drop bitfields. $$$$$$Corruption when setting heuristic dissector table UI name from Lua.$$$$$$LDAP dissector incorrectly displays filters with singleton &$$$$$$WebSocket per-message compression extentions: fail to decompress server messages (from the 2nd) due to parameter handling.$$$$$$The LL_PERIODIC_SYNC_WR_IND packet is not properly dissected (packet-btle.c)$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$AT; BT LE LL; CIGI; genl; LDAP; LIN; Logcat Text; net_dm; netfilter; nvme; SSH; TCPCL; TLS; WebSocket; ZigBee; and ZigBee ZCL$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark EXE x64 Version 4.4.7
What’s New$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2025-02 Dissection engine crash. CVE-2025-5601.$$$$$$The following bugs have been fixed:$$$$$$Wireshark does not correctly decode LIN go to sleep in TECMP and CMP. $$$$$$Dissector bug; Protocol CIGI.$$$$$$Green power packets are not dissected when proto_version == ZBEE_VERSION_GREEN_POWER.$$$$$$Packet diagrams misalign or drop bitfields. $$$$$$Corruption when setting heuristic dissector table UI name from Lua.$$$$$$LDAP dissector incorrectly displays filters with singleton &$$$$$$WebSocket per-message compression extentions: fail to decompress server messages (from the 2nd) due to parameter handling.$$$$$$The LL_PERIODIC_SYNC_WR_IND packet is not properly dissected (packet-btle.c)$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$AT; BT LE LL; CIGI; genl; LDAP; LIN; Logcat Text; net_dm; netfilter; nvme; SSH; TCPCL; TLS; WebSocket; ZigBee; and ZigBee ZCL$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark EXE x64 Version 4.4.6
What’s New$$$Bug Fixes$$$The following bugs have been fixed:$$$$$$Bug in EtherCAT dissector with ECS order. Issue 13718.$$$$$$Conversation dialog columns return to default width on each new packet in live capture. Issue 15978.$$$$$$Tests fail in LTO-enabled builds in Ubuntu/Debian. Issue 18216.$$$$$$Incorrect conditions in BFCP dissector. Issue 18717.$$$$$$Static build fails on Ubuntu 24.04 because the c-ares library isn’t found. Issue 20343.$$$$$$Flutter’s Image Picker Generated JPEG Files Detected as Malformed Packet. Issue 20355.$$$$$$QUIC dissector breaks when src and dst change. Issue 20371.$$$$$$s390x: build fail on Ubuntu PPA nighty build. Issue 20372.$$$$$$Trailing octet after IPv4 packet end is not detected or displayed in raw bytes. Issue 20423.$$$$$$[packet-ax25-nol3.c] Only call APRS dissector on UI Frames. Issue 20429.$$$$$$Wireshark hangs when refreshing interfaces with the debug console preference set to always and a file open (Windows) Issue 20434.$$$$$$BGP EVPN - Type-8 route not correctly read after addition of Max. Response Time field. Issue 20459.$$$$$$Wireshark does not correctly decode LIN go to sleep in TECMP and CMP. Issue 20463.$$$$$$MQTT-SN: WILLTOPIC message not decoded correctly (missing some flags) Issue 20476.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$ADB; ASAM CMP; AX.25; BACapp; BFCP; BGP; CP2179; DCERPC WKSSVC; DCT2000; DECT-NWK; DHCP; DOF; EAPOL-MKA; ECAT; ErlDP; Ethertype; F1AP; GSM BSSMAP; GSM DTAP; HomePlug AV; ICMP; IEEE 802.11; ITS; LDP; MQTT-SN; NAS-EPS; NR RRC; OER; PCEP; PNIO; PPP; QUAKE; QUIC; Raw; Signal PDU; TCP; TECMP; TLS; and USB DFU$$$$$$New and Updated Capture File Support$$$3GPP and pcapng$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark MSI x64 Version 4.4.6.0
What’s New$$$Bug Fixes$$$The following bugs have been fixed:$$$Bug in EtherCAT dissector with ECS order. Issue 13718.$$$Conversation dialog columns return to default width on each new packet in live capture. Issue 15978.$$$Tests fail in LTO-enabled builds in Ubuntu/Debian. Issue 18216.$$$Incorrect conditions in BFCP dissector. Issue 18717.$$$Static build fails on Ubuntu 24.04 because the c-ares library isn’t found. Issue 20343.$$$Flutter’s Image Picker Generated JPEG Files Detected as Malformed Packet. Issue 20355.$$$QUIC dissector breaks when src and dst change. Issue 20371.$$$s390x: build fail on Ubuntu PPA nighty build. Issue 20372.$$$Trailing octet after IPv4 packet end is not detected or displayed in raw bytes. Issue 20423.$$$$$$[packet-ax25-nol3.c] Only call APRS dissector on UI Frames. Issue 20429.$$$$$$Wireshark hangs when refreshing interfaces with the debug console preference set to always and a file open (Windows) Issue 20434.$$$BGP EVPN - Type-8 route not correctly read after addition of Max. Response Time field. Issue 20459.$$$Wireshark does not correctly decode LIN go to sleep in TECMP and CMP. Issue 20463.$$$MQTT-SN: WILLTOPIC message not decoded correctly (missing some flags) Issue 20476.$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$Updated Protocol Support$$$ADB; ASAM CMP; AX.25; BACapp; BFCP; BGP; CP2179; DCERPC WKSSVC; DCT2000; DECT-NWK; DHCP; DOF; EAPOL-MKA; ECAT; ErlDP; Ethertype; F1AP; GSM BSSMAP; GSM DTAP; HomePlug AV; ICMP; IEEE 802.11; ITS; LDP; MQTT-SN; NAS-EPS; NR RRC; OER; PCEP; PNIO; PPP; QUAKE; QUIC; Raw; Signal PDU; TCP; TECMP; TLS; and USB DFU$$$$$$New and Updated Capture File Support$$$3GPP and pcapng$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark EXE x64 Version 4.4.5
What’s New$$$Bug Fixes$$$The following bugs have been fixed:$$$$$$GRPC: protobuf_json only displays the truncated string value. Issue 20392.$$$$$$Wireshark crashes when clicking on a column title/header. Issue 20403.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$GNW; IPv4; NFAPI; and ProtoBuf$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark EXE x64 Version 4.4.5
What’s New$$$Bug Fixes$$$The following bugs have been fixed:$$$$$$GRPC: protobuf_json only displays the truncated string value. Issue 20392.$$$$$$Wireshark crashes when clicking on a column title/header. Issue 20403.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$GNW; IPv4; NFAPI; and ProtoBuf$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark MSI x64 Version 4.4.5.0
What’s New$$$Bug Fixes$$$The following bugs have been fixed:$$$$$$GRPC: protobuf_json only displays the truncated string value. Issue 20392.$$$$$$Wireshark crashes when clicking on a column title/header. Issue 20403.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$GNW; IPv4; NFAPI; and ProtoBuf$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark MSI x64 Version 4.4.5.0
What’s New$$$Bug Fixes$$$The following bugs have been fixed:$$$$$$GRPC: protobuf_json only displays the truncated string value. Issue 20392.$$$$$$Wireshark crashes when clicking on a column title/header. Issue 20403.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$GNW; IPv4; NFAPI; and ProtoBuf$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark MSI x64 Version 4.4.3.0
What’s New$$$Bug Fixes$$$The following bugs have been fixed:$$$$$$Potential mis-match in GSM MAP dissector for uncertainty radius and its filter key. Issue 20247.$$$$$$Macro eNodeB ID and Extended Macro eNodeB ID not decoded by User Location Information. Issue 20276.$$$$$$The NFSv2 Dissector appears to be swapping Character Special File and Directory in mode decoding. Issue 20290.$$$$$$CMake discovers Strawberry Perl’s zlib DLL when it shouldn’t. Issue 20304.$$$$$$VOIP Calls call flow displaying hours. Issue 20311.$$$$$$Fuzz job issue: fuzz-2024-12-26-7898.pcap. Issue 20313.$$$$$$sFlow: Incorrect length passed to header sample dissector. Issue 20320.$$$$$$wsutil: Should link against -lm due to missing fabs() when built with -fno-builtin. Issue 20326.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$ARTNET; ASN.1 PER; BACapp; BBLog; BT BR/EDR RF; CQL; Diameter; DOF; ECMP; FiveCo RAP; FTDI FT; GSM COMMON; GTPv2; HCI_MON; HSRP; HTTP2; ICMPv6; IEEE 802.11; Kafka; LTE RRC; MBIM; MMS; Modbus/TCP; MPEG PES; NAS-EPS; NFS; NGAP; NR RRC; PLDM; PN-DCP; POP; ProtoBuf; PTP; RLC; RPC; RTCP; sFlow; SIP; SRT; TCP; UCP; USBCCID; Wi-SUN; and ZigBee ZCL$$$$$$New and Updated Capture File Support$$$CLLog EMS ERF$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark EXE x64 Version 4.4.3
What’s New$$$Bug Fixes$$$The following bugs have been fixed:$$$$$$Potential mis-match in GSM MAP dissector for uncertainty radius and its filter key. Issue 20247.$$$$$$Macro eNodeB ID and Extended Macro eNodeB ID not decoded by User Location Information. Issue 20276.$$$$$$The NFSv2 Dissector appears to be swapping Character Special File and Directory in mode decoding. Issue 20290.$$$$$$CMake discovers Strawberry Perl’s zlib DLL when it shouldn’t. Issue 20304.$$$$$$VOIP Calls call flow displaying hours. Issue 20311.$$$$$$Fuzz job issue: fuzz-2024-12-26-7898.pcap. Issue 20313.$$$$$$sFlow: Incorrect length passed to header sample dissector. Issue 20320.$$$$$$wsutil: Should link against -lm due to missing fabs() when built with -fno-builtin. Issue 20326.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$ARTNET; ASN.1 PER; BACapp; BBLog; BT BR/EDR RF; CQL; Diameter; DOF; ECMP; FiveCo RAP; FTDI FT; GSM COMMON; GTPv2; HCI_MON; HSRP; HTTP2; ICMPv6; IEEE 802.11; Kafka; LTE RRC; MBIM; MMS; Modbus/TCP; MPEG PES; NAS-EPS; NFS; NGAP; NR RRC; PLDM; PN-DCP; POP; ProtoBuf; PTP; RLC; RPC; RTCP; sFlow; SIP; SRT; TCP; UCP; USBCCID; Wi-SUN; and ZigBee ZCL$$$$$$New and Updated Capture File Support$$$CLLog EMS ERF$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark MSI x64 Version 4.4.2.0
What’s New$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2024-14 FiveCo RAP dissector infinite loop. Issue 20176.$$$$$$wnpa-sec-2024-15 ECMP dissector crash. Issue 20214.$$$$$$The following bugs have been fixed:$$$$$$CIP I/O is not detected by enip filter anymore. Issue 19517.$$$$$$Fuzz job issue: fuzz-2024-09-03-7550.pcap. Issue 20041.$$$$$$OSS-Fuzz 71476: wireshark:fuzzshark_ip_proto-udp: Index-out-of-bounds in DOFObjectID_Create_Unmarshal. Issue 20065.$$$$$$JA4_c hashes an empty field to e3b0c44298fc when it should be 000000000000. Issue 20066.$$$$$$Opening Wireshark 4.4.0 on macOS 15.0 disconnects iPhone Mirroring. Issue 20082.$$$$$$PTP analysis loses track of message associations in case of sequence number resets. Issue 20099.$$$$$$USB CCID: response packet in case SetParameters command is unsupported is flagged as malformed. Issue 20107.$$$$$$dumpcap crashes when run from TShark with a capture filter. Issue 20108.$$$$$$SRT dissector: The StreamID (SID) in the handshake extension is displayed without regarding the control characters and with NUL as terminating. Issue 20113.$$$$$$Ghost error message on POP3 packets. Issue 20124.$$$$$$Building against c-ares 1.34 fails. Issue 20125.$$$$$$D-Bus is not optional anymore. Issue 20126.$$$$$$macOS Intel DMGs aren’t fully notarized. Issue 20129.$$$$$$Incorrect name for MLD Capabilities and Operations Present flag in dissection of MLD Capabilities for MLO wifi-7 capture. Issue 20134.$$$$$$CQL Malformed Packet v4 S ? C Type RESULT: Prepared[Malformed Packet] Issue 20142.$$$$$$Wi-Fi: 256 Block Ack (BA) is not parsed properly. Issue 20156.$$$$$$BACnet ReadPropertyMultiple request Maximum allowed recursion depth reached. Issue 20159.$$$$$$Statistics?I/O Graph crashes when using simple moving average. Issue 20163.$$$$$$HTTP2 body decompression fails on DATA with a single padded frame. Issue 20167.$$$$$$Compiler warning for ui/tap-rtp-common.c (ignoring return value) Issue 20169.$$$$$$SIP dissector bug due to be-route param in VIA header. Issue 20173.$$$$$$Coredump after trying to open Follow TCP stream Issue 20174.$$$$$$Protobuf JSON mapping error. Issue 20182.$$$$$$Display filter !stp.pvst.origvlan in { vlan.id } causes a crash (Version 4.4.1) Issue 20183.$$$$$$Extcap plugins shipped with Wireshark Portable are not found in version 4.4.1. Issue 20184.$$$$$$IEEE 802.11be: Wrong regulatory info in HE Operation IE in Beacon frame. Issue 20187.$$$$$$Wireshark 4.4.1 does not decode RTCP packets. Issue 20188.$$$$$$Qt: Display filter sub-menu can only be opened on the triangle; not the full name. Issue 20190.$$$$$$Qt: Changing the display filter does not update the Conversations or Endpoints dialogs. Issue 20191.$$$$$$MODBUS Dissector bug. Issue 20192.$$$$$$Modbus dissector bug - Field Occurence and Layer Operator modbus.bitval field. Issue 20193.$$$$$$Wireshark crashes when a field is dragged from packet details towards the find input. Issue 20204.$$$$$$Lua DissectorTable() : set (10;11) unexpected behavior in locales with comma as decimal separator. Issue 20216.$$$$$$The TCP dissector no longer falls back to using the client port as a criterion for selecting a payload dissector when the server port does not select a payload dissector (except for port 20; active FTP). This behavior can be changed using the Client port dissectors preference.$$$$$$Display filters now correctly handle floating point conversion errors.$$$$$$The Lua API now has better support for comma-separated ranges in different locales.$$$$$$New and Updated Features$$$The TShark syntax for dumping only fields with a certain prefix has changed from -G fields prefix to -G fields;prefix. This allows tshark -G fields to again support also specifying the configuration profile to use.$$$$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$ARTNET; ASN.1 PER; BACapp; BT BR/EDR; CQL; DOF; ECMP; ENIP; FiveCo RAP; Frame; FTDI FT; HSRP; HTTP/2; ICMPv6; IEEE 802.11; MBTCP; MMS; MPEG PES; PN-DCP; POP; ProtoBuf; PTP; RPC; RT
Wireshark EXE x64 Version 4.4.2
Wireshark 4.4.2 Release Notes$$$What’s New$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2024-14 FiveCo RAP dissector infinite loop. Issue 20176.$$$$$$wnpa-sec-2024-15 ECMP dissector crash. Issue 20214.$$$$$$The following bugs have been fixed:$$$$$$CIP I/O is not detected by enip filter anymore. Issue 19517.$$$$$$Fuzz job issue: fuzz-2024-09-03-7550.pcap. Issue 20041.$$$$$$OSS-Fuzz 71476: wireshark:fuzzshark_ip_proto-udp: Index-out-of-bounds in DOFObjectID_Create_Unmarshal. Issue 20065.$$$$$$JA4_c hashes an empty field to e3b0c44298fc when it should be 000000000000. Issue 20066.$$$$$$Opening Wireshark 4.4.0 on macOS 15.0 disconnects iPhone Mirroring. Issue 20082.$$$$$$PTP analysis loses track of message associations in case of sequence number resets. Issue 20099.$$$$$$USB CCID: response packet in case SetParameters command is unsupported is flagged as malformed. Issue 20107.$$$$$$dumpcap crashes when run from TShark with a capture filter. Issue 20108.$$$$$$SRT dissector: The StreamID (SID) in the handshake extension is displayed without regarding the control characters and with NUL as terminating. Issue 20113.$$$$$$Ghost error message on POP3 packets. Issue 20124.$$$$$$Building against c-ares 1.34 fails. Issue 20125.$$$$$$D-Bus is not optional anymore. Issue 20126.$$$$$$macOS Intel DMGs aren’t fully notarized. Issue 20129.$$$$$$Incorrect name for MLD Capabilities and Operations Present flag in dissection of MLD Capabilities for MLO wifi-7 capture. Issue 20134.$$$$$$CQL Malformed Packet v4 S ? C Type RESULT: Prepared[Malformed Packet] Issue 20142.$$$$$$Wi-Fi: 256 Block Ack (BA) is not parsed properly. Issue 20156.$$$$$$BACnet ReadPropertyMultiple request Maximum allowed recursion depth reached. Issue 20159.$$$$$$Statistics?I/O Graph crashes when using simple moving average. Issue 20163.$$$$$$HTTP2 body decompression fails on DATA with a single padded frame. Issue 20167.$$$$$$Compiler warning for ui/tap-rtp-common.c (ignoring return value) Issue 20169.$$$$$$SIP dissector bug due to be-route param in VIA header. Issue 20173.$$$$$$Coredump after trying to open Follow TCP stream Issue 20174.$$$$$$Protobuf JSON mapping error. Issue 20182.$$$$$$Display filter !stp.pvst.origvlan in { vlan.id } causes a crash (Version 4.4.1) Issue 20183.$$$$$$Extcap plugins shipped with Wireshark Portable are not found in version 4.4.1. Issue 20184.$$$$$$IEEE 802.11be: Wrong regulatory info in HE Operation IE in Beacon frame. Issue 20187.$$$$$$Wireshark 4.4.1 does not decode RTCP packets. Issue 20188.$$$$$$Qt: Display filter sub-menu can only be opened on the triangle; not the full name. Issue 20190.$$$$$$Qt: Changing the display filter does not update the Conversations or Endpoints dialogs. Issue 20191.$$$$$$MODBUS Dissector bug. Issue 20192.$$$$$$Modbus dissector bug - Field Occurence and Layer Operator modbus.bitval field. Issue 20193.$$$$$$Wireshark crashes when a field is dragged from packet details towards the find input. Issue 20204.$$$$$$Lua DissectorTable() : set (10;11) unexpected behavior in locales with comma as decimal separator. Issue 20216.$$$$$$The TCP dissector no longer falls back to using the client port as a criterion for selecting a payload dissector when the server port does not select a payload dissector (except for port 20; active FTP). This behavior can be changed using the Client port dissectors preference.$$$$$$Display filters now correctly handle floating point conversion errors.$$$$$$The Lua API now has better support for comma-separated ranges in different locales.$$$$$$New and Updated Features$$$The TShark syntax for dumping only fields with a certain prefix has changed from -G fields prefix to -G fields;prefix. This allows tshark -G fields to again support also specifying the configuration profile to use.$$$$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$ARTNET; ASN.1 PER; BACapp; BT BR/EDR; CQL; DOF; ECMP; ENIP; FiveCo RAP; Frame; FTDI FT; HSRP; HTTP/2; ICMPv6; IEEE 802.11; MBTCP; MMS; MPEG PES; PN-D
Wireshark MSI x64 Version 4.4.2.0
What’s New$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2024-14 FiveCo RAP dissector infinite loop. Issue 20176.$$$$$$wnpa-sec-2024-15 ECMP dissector crash. Issue 20214.$$$$$$The following bugs have been fixed:$$$$$$CIP I/O is not detected by enip filter anymore. Issue 19517.$$$$$$Fuzz job issue: fuzz-2024-09-03-7550.pcap. Issue 20041.$$$$$$OSS-Fuzz 71476: wireshark:fuzzshark_ip_proto-udp: Index-out-of-bounds in DOFObjectID_Create_Unmarshal. Issue 20065.$$$$$$JA4_c hashes an empty field to e3b0c44298fc when it should be 000000000000. Issue 20066.$$$$$$Opening Wireshark 4.4.0 on macOS 15.0 disconnects iPhone Mirroring. Issue 20082.$$$$$$PTP analysis loses track of message associations in case of sequence number resets. Issue 20099.$$$$$$USB CCID: response packet in case SetParameters command is unsupported is flagged as malformed. Issue 20107.$$$$$$dumpcap crashes when run from TShark with a capture filter. Issue 20108.$$$$$$SRT dissector: The StreamID (SID) in the handshake extension is displayed without regarding the control characters and with NUL as terminating. Issue 20113.$$$$$$Ghost error message on POP3 packets. Issue 20124.$$$$$$Building against c-ares 1.34 fails. Issue 20125.$$$$$$D-Bus is not optional anymore. Issue 20126.$$$$$$macOS Intel DMGs aren’t fully notarized. Issue 20129.$$$$$$Incorrect name for MLD Capabilities and Operations Present flag in dissection of MLD Capabilities for MLO wifi-7 capture. Issue 20134.$$$$$$CQL Malformed Packet v4 S ? C Type RESULT: Prepared[Malformed Packet] Issue 20142.$$$$$$Wi-Fi: 256 Block Ack (BA) is not parsed properly. Issue 20156.$$$$$$BACnet ReadPropertyMultiple request Maximum allowed recursion depth reached. Issue 20159.$$$$$$Statistics?I/O Graph crashes when using simple moving average. Issue 20163.$$$$$$HTTP2 body decompression fails on DATA with a single padded frame. Issue 20167.$$$$$$Compiler warning for ui/tap-rtp-common.c (ignoring return value) Issue 20169.$$$$$$SIP dissector bug due to be-route param in VIA header. Issue 20173.$$$$$$Coredump after trying to open Follow TCP stream Issue 20174.$$$$$$Protobuf JSON mapping error. Issue 20182.$$$$$$Display filter !stp.pvst.origvlan in { vlan.id } causes a crash (Version 4.4.1) Issue 20183.$$$$$$Extcap plugins shipped with Wireshark Portable are not found in version 4.4.1. Issue 20184.$$$$$$IEEE 802.11be: Wrong regulatory info in HE Operation IE in Beacon frame. Issue 20187.$$$$$$Wireshark 4.4.1 does not decode RTCP packets. Issue 20188.$$$$$$Qt: Display filter sub-menu can only be opened on the triangle; not the full name. Issue 20190.$$$$$$Qt: Changing the display filter does not update the Conversations or Endpoints dialogs. Issue 20191.$$$$$$MODBUS Dissector bug. Issue 20192.$$$$$$Modbus dissector bug - Field Occurence and Layer Operator modbus.bitval field. Issue 20193.$$$$$$Wireshark crashes when a field is dragged from packet details towards the find input. Issue 20204.$$$$$$Lua DissectorTable() : set (10;11) unexpected behavior in locales with comma as decimal separator. Issue 20216.$$$$$$The TCP dissector no longer falls back to using the client port as a criterion for selecting a payload dissector when the server port does not select a payload dissector (except for port 20; active FTP). This behavior can be changed using the Client port dissectors preference.$$$$$$Display filters now correctly handle floating point conversion errors.$$$$$$The Lua API now has better support for comma-separated ranges in different locales.$$$$$$New and Updated Features$$$The TShark syntax for dumping only fields with a certain prefix has changed from -G fields prefix to -G fields;prefix. This allows tshark -G fields to again support also specifying the configuration profile to use.$$$$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$ARTNET; ASN.1 PER; BACapp; BT BR/EDR; CQL; DOF; ECMP; ENIP; FiveCo RAP; Frame; FTDI FT; HSRP; HTTP/2; ICMPv6; IEEE 802.11; MBTCP; MMS; MPEG PES; PN-DCP; POP; ProtoBuf; PTP; RPC; RT
Wireshark EXE x64 Version 4.4.2
Wireshark 4.4.2 Release Notes$$$What’s New$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2024-14 FiveCo RAP dissector infinite loop. Issue 20176.$$$$$$wnpa-sec-2024-15 ECMP dissector crash. Issue 20214.$$$$$$The following bugs have been fixed:$$$$$$CIP I/O is not detected by enip filter anymore. Issue 19517.$$$$$$Fuzz job issue: fuzz-2024-09-03-7550.pcap. Issue 20041.$$$$$$OSS-Fuzz 71476: wireshark:fuzzshark_ip_proto-udp: Index-out-of-bounds in DOFObjectID_Create_Unmarshal. Issue 20065.$$$$$$JA4_c hashes an empty field to e3b0c44298fc when it should be 000000000000. Issue 20066.$$$$$$Opening Wireshark 4.4.0 on macOS 15.0 disconnects iPhone Mirroring. Issue 20082.$$$$$$PTP analysis loses track of message associations in case of sequence number resets. Issue 20099.$$$$$$USB CCID: response packet in case SetParameters command is unsupported is flagged as malformed. Issue 20107.$$$$$$dumpcap crashes when run from TShark with a capture filter. Issue 20108.$$$$$$SRT dissector: The StreamID (SID) in the handshake extension is displayed without regarding the control characters and with NUL as terminating. Issue 20113.$$$$$$Ghost error message on POP3 packets. Issue 20124.$$$$$$Building against c-ares 1.34 fails. Issue 20125.$$$$$$D-Bus is not optional anymore. Issue 20126.$$$$$$macOS Intel DMGs aren’t fully notarized. Issue 20129.$$$$$$Incorrect name for MLD Capabilities and Operations Present flag in dissection of MLD Capabilities for MLO wifi-7 capture. Issue 20134.$$$$$$CQL Malformed Packet v4 S ? C Type RESULT: Prepared[Malformed Packet] Issue 20142.$$$$$$Wi-Fi: 256 Block Ack (BA) is not parsed properly. Issue 20156.$$$$$$BACnet ReadPropertyMultiple request Maximum allowed recursion depth reached. Issue 20159.$$$$$$Statistics?I/O Graph crashes when using simple moving average. Issue 20163.$$$$$$HTTP2 body decompression fails on DATA with a single padded frame. Issue 20167.$$$$$$Compiler warning for ui/tap-rtp-common.c (ignoring return value) Issue 20169.$$$$$$SIP dissector bug due to be-route param in VIA header. Issue 20173.$$$$$$Coredump after trying to open Follow TCP stream Issue 20174.$$$$$$Protobuf JSON mapping error. Issue 20182.$$$$$$Display filter !stp.pvst.origvlan in { vlan.id } causes a crash (Version 4.4.1) Issue 20183.$$$$$$Extcap plugins shipped with Wireshark Portable are not found in version 4.4.1. Issue 20184.$$$$$$IEEE 802.11be: Wrong regulatory info in HE Operation IE in Beacon frame. Issue 20187.$$$$$$Wireshark 4.4.1 does not decode RTCP packets. Issue 20188.$$$$$$Qt: Display filter sub-menu can only be opened on the triangle; not the full name. Issue 20190.$$$$$$Qt: Changing the display filter does not update the Conversations or Endpoints dialogs. Issue 20191.$$$$$$MODBUS Dissector bug. Issue 20192.$$$$$$Modbus dissector bug - Field Occurence and Layer Operator modbus.bitval field. Issue 20193.$$$$$$Wireshark crashes when a field is dragged from packet details towards the find input. Issue 20204.$$$$$$Lua DissectorTable() : set (10;11) unexpected behavior in locales with comma as decimal separator. Issue 20216.$$$$$$The TCP dissector no longer falls back to using the client port as a criterion for selecting a payload dissector when the server port does not select a payload dissector (except for port 20; active FTP). This behavior can be changed using the Client port dissectors preference.$$$$$$Display filters now correctly handle floating point conversion errors.$$$$$$The Lua API now has better support for comma-separated ranges in different locales.$$$$$$New and Updated Features$$$The TShark syntax for dumping only fields with a certain prefix has changed from -G fields prefix to -G fields;prefix. This allows tshark -G fields to again support also specifying the configuration profile to use.$$$$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$ARTNET; ASN.1 PER; BACapp; BT BR/EDR; CQL; DOF; ECMP; ENIP; FiveCo RAP; Frame; FTDI FT; HSRP; HTTP/2; ICMPv6; IEEE 802.11; MBTCP; MMS; MPEG PES; PN-D
Wireshark EXE x64 Version 4.4.1
Wireshark 4.4.1 Release Notes$$$What is Wireshark?$$$$$$What’s New$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2024-12 ITS dissector crash. Issue 20026.$$$$$$wnpa-sec-2024-13 AppleTalk and RELOAD Framing dissector crashes. Issue 20114.$$$$$$The following bugs have been fixed:$$$$$$Refresh interface during live-capture leads to corrupt interface handling. Issue 11176.$$$$$$Media type application/octet-stream registered for both Thread and UASIP. Issue 14729.$$$$$$Extcap toolbar stops working when new interface is added. Issue 19854.$$$$$$Decoding error ITS CPM version 2.1.1. Issue 19886.$$$$$$Build error in 4.3.0: sync_pipe_run_command_actual error: argument 2 is null but the corresponding size argument 3 value is 512004 [-Werror=nonnull] Issue 19930.$$$$$$html2text.py doesn’t handle the <sup> tag. Issue 20020.$$$$$$Incorrect NetFlow v8 TOS AS aggregation dissection. Issue 20021.$$$$$$The Windows packages don’t ship with the IP address plugin. Issue 20030.$$$$$$O_PATH is Linux-and-FreeBSD-specific. Issue 20031.$$$$$$Wireshark 4.4.0 doesn’t install USBcap USBcapCMD in the correct directory. Issue 20040.$$$$$$OER dissector is not considering the preamble if ASN.1 SEQUENCE definition includes extension marker but no OPTIONAL items. Issue 20044.$$$$$$Bluetooth classic L2CAP incorrect dissection with connectionless reception channel. Issue 20047.$$$$$$Profile auto switch filters : Grayed Display Filter Expression dialog box when opened from Configuration Profiles dialog box. Issue 20049.$$$$$$Wireshark 4.4.0 / macOS 14.6.1 wifi if monitor mode. Issue 20051.$$$$$$TECMP Data Type passes too much data to sub dissectors. Issue 20052.$$$$$$Wireshark and tshark 4.4.0 ignore extcap options specified on the command line. Issue 20054.$$$$$$Cannot open release notes due to incorrect path with duplicated directory components. Issue 20055.$$$$$$Unable to open Release Notes from the Help menu. Issue 20056.$$$$$$No capture interfaces if Wireshark is started from command line with certain paths. Issue 20057.$$$$$$Wireshark 4.4.0 extcap path change breaks third party extcap installers. Issue 20069.$$$$$$Fuzz job UTF-8 encoding issue: fuzz-2024-09-10-7618.pcap. Issue 20071.$$$$$$Unable to create larger files than 99 size units. Issue 20079.$$$$$$Opening Wireshark 4.4.0 on macOS 15.0 disconnects iPhone Mirroring. Issue 20082.$$$$$$PRP trailer not shown for L2 IEC 61850 GOOSE packets in 4.4.0 (was working in 4.2.7) Issue 20088.$$$$$$GUI lags because NetworkManager keeps turning 802.11 monitor mode off. Issue 20090.
Wireshark MSI x64 Version 4.4.1.0
What’s New$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2024-12 ITS dissector crash. Issue 20026.$$$$$$wnpa-sec-2024-13 AppleTalk and RELOAD Framing dissector crashes. Issue 20114.$$$$$$The following bugs have been fixed:$$$$$$Refresh interface during live-capture leads to corrupt interface handling. Issue 11176.$$$$$$Media type application/octet-stream registered for both Thread and UASIP. Issue 14729.$$$$$$Extcap toolbar stops working when new interface is added. Issue 19854.$$$$$$Decoding error ITS CPM version 2.1.1. Issue 19886.$$$$$$Build error in 4.3.0: sync_pipe_run_command_actual error: argument 2 is null but the corresponding size argument 3 value is 512004 [-Werror=nonnull] Issue 19930.$$$$$$html2text.py doesn’t handle the <sup> tag. Issue 20020.$$$$$$Incorrect NetFlow v8 TOS AS aggregation dissection. Issue 20021.$$$$$$The Windows packages don’t ship with the IP address plugin. Issue 20030.$$$$$$O_PATH is Linux-and-FreeBSD-specific. Issue 20031.$$$$$$Wireshark 4.4.0 doesn’t install USBcap USBcapCMD in the correct directory. Issue 20040.$$$$$$OER dissector is not considering the preamble if ASN.1 SEQUENCE definition includes extension marker but no OPTIONAL items. Issue 20044.$$$$$$Bluetooth classic L2CAP incorrect dissection with connectionless reception channel. Issue 20047.$$$$$$Profile auto switch filters : Grayed Display Filter Expression dialog box when opened from Configuration Profiles dialog box. Issue 20049.$$$$$$Wireshark 4.4.0 / macOS 14.6.1 wifi if monitor mode. Issue 20051.$$$$$$TECMP Data Type passes too much data to sub dissectors. Issue 20052.$$$$$$Wireshark and tshark 4.4.0 ignore extcap options specified on the command line. Issue 20054.$$$$$$Cannot open release notes due to incorrect path with duplicated directory components. Issue 20055.$$$$$$Unable to open Release Notes from the Help menu. Issue 20056.$$$$$$No capture interfaces if Wireshark is started from command line with certain paths. Issue 20057.$$$$$$Wireshark 4.4.0 extcap path change breaks third party extcap installers. Issue 20069.$$$$$$Fuzz job UTF-8 encoding issue: fuzz-2024-09-10-7618.pcap. Issue 20071.$$$$$$Unable to create larger files than 99 size units. Issue 20079.$$$$$$Opening Wireshark 4.4.0 on macOS 15.0 disconnects iPhone Mirroring. Issue 20082.$$$$$$PRP trailer not shown for L2 IEC 61850 GOOSE packets in 4.4.0 (was working in 4.2.7) Issue 20088.$$$$$$GUI lags because NetworkManager keeps turning 802.11 monitor mode off. Issue 20090.$$$$$$Error while getting Bluetooth application process id by <shell:ps -A | grep com.*android.bluetooth> Issue 20100.$$$$$$Fuzz job assertion: randpkt-2024-10-05-7200.pcap. Issue 20110.
Wireshark EXE x64 Version 4.4.1
Wireshark 4.4.1 Release Notes$$$What is Wireshark?$$$$$$What’s New$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2024-12 ITS dissector crash. Issue 20026.$$$$$$wnpa-sec-2024-13 AppleTalk and RELOAD Framing dissector crashes. Issue 20114.$$$$$$The following bugs have been fixed:$$$$$$Refresh interface during live-capture leads to corrupt interface handling. Issue 11176.$$$$$$Media type application/octet-stream registered for both Thread and UASIP. Issue 14729.$$$$$$Extcap toolbar stops working when new interface is added. Issue 19854.$$$$$$Decoding error ITS CPM version 2.1.1. Issue 19886.$$$$$$Build error in 4.3.0: sync_pipe_run_command_actual error: argument 2 is null but the corresponding size argument 3 value is 512004 [-Werror=nonnull] Issue 19930.$$$$$$html2text.py doesn’t handle the <sup> tag. Issue 20020.$$$$$$Incorrect NetFlow v8 TOS AS aggregation dissection. Issue 20021.$$$$$$The Windows packages don’t ship with the IP address plugin. Issue 20030.$$$$$$O_PATH is Linux-and-FreeBSD-specific. Issue 20031.$$$$$$Wireshark 4.4.0 doesn’t install USBcap USBcapCMD in the correct directory. Issue 20040.$$$$$$OER dissector is not considering the preamble if ASN.1 SEQUENCE definition includes extension marker but no OPTIONAL items. Issue 20044.$$$$$$Bluetooth classic L2CAP incorrect dissection with connectionless reception channel. Issue 20047.$$$$$$Profile auto switch filters : Grayed Display Filter Expression dialog box when opened from Configuration Profiles dialog box. Issue 20049.$$$$$$Wireshark 4.4.0 / macOS 14.6.1 wifi if monitor mode. Issue 20051.$$$$$$TECMP Data Type passes too much data to sub dissectors. Issue 20052.$$$$$$Wireshark and tshark 4.4.0 ignore extcap options specified on the command line. Issue 20054.$$$$$$Cannot open release notes due to incorrect path with duplicated directory components. Issue 20055.$$$$$$Unable to open Release Notes from the Help menu. Issue 20056.$$$$$$No capture interfaces if Wireshark is started from command line with certain paths. Issue 20057.$$$$$$Wireshark 4.4.0 extcap path change breaks third party extcap installers. Issue 20069.$$$$$$Fuzz job UTF-8 encoding issue: fuzz-2024-09-10-7618.pcap. Issue 20071.$$$$$$Unable to create larger files than 99 size units. Issue 20079.$$$$$$Opening Wireshark 4.4.0 on macOS 15.0 disconnects iPhone Mirroring. Issue 20082.$$$$$$PRP trailer not shown for L2 IEC 61850 GOOSE packets in 4.4.0 (was working in 4.2.7) Issue 20088.$$$$$$GUI lags because NetworkManager keeps turning 802.11 monitor mode off. Issue 20090.
Wireshark MSI x64 Version 4.4.1.0
What’s New$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2024-12 ITS dissector crash. Issue 20026.$$$$$$wnpa-sec-2024-13 AppleTalk and RELOAD Framing dissector crashes. Issue 20114.$$$$$$The following bugs have been fixed:$$$$$$Refresh interface during live-capture leads to corrupt interface handling. Issue 11176.$$$$$$Media type application/octet-stream registered for both Thread and UASIP. Issue 14729.$$$$$$Extcap toolbar stops working when new interface is added. Issue 19854.$$$$$$Decoding error ITS CPM version 2.1.1. Issue 19886.$$$$$$Build error in 4.3.0: sync_pipe_run_command_actual error: argument 2 is null but the corresponding size argument 3 value is 512004 [-Werror=nonnull] Issue 19930.$$$$$$html2text.py doesn’t handle the <sup> tag. Issue 20020.$$$$$$Incorrect NetFlow v8 TOS AS aggregation dissection. Issue 20021.$$$$$$The Windows packages don’t ship with the IP address plugin. Issue 20030.$$$$$$O_PATH is Linux-and-FreeBSD-specific. Issue 20031.$$$$$$Wireshark 4.4.0 doesn’t install USBcap USBcapCMD in the correct directory. Issue 20040.$$$$$$OER dissector is not considering the preamble if ASN.1 SEQUENCE definition includes extension marker but no OPTIONAL items. Issue 20044.$$$$$$Bluetooth classic L2CAP incorrect dissection with connectionless reception channel. Issue 20047.$$$$$$Profile auto switch filters : Grayed Display Filter Expression dialog box when opened from Configuration Profiles dialog box. Issue 20049.$$$$$$Wireshark 4.4.0 / macOS 14.6.1 wifi if monitor mode. Issue 20051.$$$$$$TECMP Data Type passes too much data to sub dissectors. Issue 20052.$$$$$$Wireshark and tshark 4.4.0 ignore extcap options specified on the command line. Issue 20054.$$$$$$Cannot open release notes due to incorrect path with duplicated directory components. Issue 20055.$$$$$$Unable to open Release Notes from the Help menu. Issue 20056.$$$$$$No capture interfaces if Wireshark is started from command line with certain paths. Issue 20057.$$$$$$Wireshark 4.4.0 extcap path change breaks third party extcap installers. Issue 20069.$$$$$$Fuzz job UTF-8 encoding issue: fuzz-2024-09-10-7618.pcap. Issue 20071.$$$$$$Unable to create larger files than 99 size units. Issue 20079.$$$$$$Opening Wireshark 4.4.0 on macOS 15.0 disconnects iPhone Mirroring. Issue 20082.$$$$$$PRP trailer not shown for L2 IEC 61850 GOOSE packets in 4.4.0 (was working in 4.2.7) Issue 20088.$$$$$$GUI lags because NetworkManager keeps turning 802.11 monitor mode off. Issue 20090.$$$$$$Error while getting Bluetooth application process id by <shell:ps -A | grep com.*android.bluetooth> Issue 20100.$$$$$$Fuzz job assertion: randpkt-2024-10-05-7200.pcap. Issue 20110.
Wireshark EXE x64 Version 4.4.0
Wireshark 4.4.0 Release Notes$$$This is the first release of the 4.4 branch.$$$$$$What is Wireshark?$$$Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting; analysis; development and education.$$$$$$Wireshark is hosted by the Wireshark Foundation; a nonprofit which promotes protocol analysis education. Wireshark and the foundation depend on your contributions in order to do their work. If you or your organization would like to contribute or become a sponsor; please visit wiresharkfoundation.org.$$$$$$What’s New$$$Many improvements and fixes to the graphing dialogs; including I/O Graphs; Flow Graph / VoIP Calls; and TCP Stream Graphs.$$$$$$Wireshark now supports automatic profile switching. You can associate a display filter with a configuration profile; and when you open a capture file that matches the filter; Wireshark will automatically switch to that profile.$$$$$$Support for Lua 5.3 and 5.4 has been added; and support for Lua 5.1 and 5.2 has been removed. The Windows and macOS installers now ship with Lua 5.4.6.$$$$$$Improved display filter support for value strings (optional string representations for numeric fields).$$$$$$Display filter functions can be implemented as plugins; similar to protocol dissectors and file parsers.$$$$$$Display filters can be translated to pcap filters using Edit › Copy › Display filter as pcap filter if each display filter field has a corresponding pcap filter equivalent.$$$$$$Custom columns can be defined using any valid field expression; such as display filter functions; packet slices; arithmetic calculations; logical tests; raw byte addressing; and protocol layer modifiers.$$$$$$Custom output fields for tshark -e can also be defined using any valid field expression.$$$$$$Wireshark can be built with the zlib-ng instead of zlib for compressed file support. Zlib-ng is substantially faster than zlib. The official Windows and macOS packages include this feature.$$$$$$Many other improvements have been made. See the “New and Updated Features” section below for more details.$$$$$$Refer - https://www.wireshark.org/docs/relnotes/wireshark-4.4.0.html
Wireshark MSI x64 Version 4.4.0.0
Wireshark 4.4.0 Release Notes$$$This is the first release of the 4.4 branch.$$$$$$What is Wireshark?$$$Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting; analysis; development and education.$$$$$$Wireshark is hosted by the Wireshark Foundation; a nonprofit which promotes protocol analysis education. Wireshark and the foundation depend on your contributions in order to do their work. If you or your organization would like to contribute or become a sponsor; please visit wiresharkfoundation.org.$$$$$$What’s New$$$Many improvements and fixes to the graphing dialogs; including I/O Graphs; Flow Graph / VoIP Calls; and TCP Stream Graphs.$$$$$$Wireshark now supports automatic profile switching. You can associate a display filter with a configuration profile; and when you open a capture file that matches the filter; Wireshark will automatically switch to that profile.$$$$$$Support for Lua 5.3 and 5.4 has been added; and support for Lua 5.1 and 5.2 has been removed. The Windows and macOS installers now ship with Lua 5.4.6.$$$$$$Improved display filter support for value strings (optional string representations for numeric fields).$$$$$$Display filter functions can be implemented as plugins; similar to protocol dissectors and file parsers.$$$$$$Display filters can be translated to pcap filters using Edit › Copy › Display filter as pcap filter if each display filter field has a corresponding pcap filter equivalent.$$$$$$Custom columns can be defined using any valid field expression; such as display filter functions; packet slices; arithmetic calculations; logical tests; raw byte addressing; and protocol layer modifiers.$$$$$$Custom output fields for tshark -e can also be defined using any valid field expression.$$$$$$Wireshark can be built with the zlib-ng instead of zlib for compressed file support. Zlib-ng is substantially faster than zlib. The official Windows and macOS packages include this feature.$$$$$$Many other improvements have been made. See the “New and Updated Features” section below for more details.$$$$$$New and Updated Features$$$$$$For more details -Refer https://www.wireshark.org/docs/relnotes/wireshark-4.4.0.html
Wireshark EXE x64 Version 4.4.0
Wireshark 4.4.0 Release Notes$$$This is the first release of the 4.4 branch.$$$$$$What is Wireshark?$$$Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting; analysis; development and education.$$$$$$Wireshark is hosted by the Wireshark Foundation; a nonprofit which promotes protocol analysis education. Wireshark and the foundation depend on your contributions in order to do their work. If you or your organization would like to contribute or become a sponsor; please visit wiresharkfoundation.org.$$$$$$What’s New$$$Many improvements and fixes to the graphing dialogs; including I/O Graphs; Flow Graph / VoIP Calls; and TCP Stream Graphs.$$$$$$Wireshark now supports automatic profile switching. You can associate a display filter with a configuration profile; and when you open a capture file that matches the filter; Wireshark will automatically switch to that profile.$$$$$$Support for Lua 5.3 and 5.4 has been added; and support for Lua 5.1 and 5.2 has been removed. The Windows and macOS installers now ship with Lua 5.4.6.$$$$$$Improved display filter support for value strings (optional string representations for numeric fields).$$$$$$Display filter functions can be implemented as plugins; similar to protocol dissectors and file parsers.$$$$$$Display filters can be translated to pcap filters using Edit › Copy › Display filter as pcap filter if each display filter field has a corresponding pcap filter equivalent.$$$$$$Custom columns can be defined using any valid field expression; such as display filter functions; packet slices; arithmetic calculations; logical tests; raw byte addressing; and protocol layer modifiers.$$$$$$Custom output fields for tshark -e can also be defined using any valid field expression.$$$$$$Wireshark can be built with the zlib-ng instead of zlib for compressed file support. Zlib-ng is substantially faster than zlib. The official Windows and macOS packages include this feature.$$$$$$Many other improvements have been made. See the “New and Updated Features” section below for more details.$$$$$$Refer - https://www.wireshark.org/docs/relnotes/wireshark-4.4.0.html
Wireshark MSI x64 Version 4.4.0.0
Wireshark 4.4.0 Release Notes$$$This is the first release of the 4.4 branch.$$$$$$What is Wireshark?$$$Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting; analysis; development and education.$$$$$$Wireshark is hosted by the Wireshark Foundation; a nonprofit which promotes protocol analysis education. Wireshark and the foundation depend on your contributions in order to do their work. If you or your organization would like to contribute or become a sponsor; please visit wiresharkfoundation.org.$$$$$$What’s New$$$Many improvements and fixes to the graphing dialogs; including I/O Graphs; Flow Graph / VoIP Calls; and TCP Stream Graphs.$$$$$$Wireshark now supports automatic profile switching. You can associate a display filter with a configuration profile; and when you open a capture file that matches the filter; Wireshark will automatically switch to that profile.$$$$$$Support for Lua 5.3 and 5.4 has been added; and support for Lua 5.1 and 5.2 has been removed. The Windows and macOS installers now ship with Lua 5.4.6.$$$$$$Improved display filter support for value strings (optional string representations for numeric fields).$$$$$$Display filter functions can be implemented as plugins; similar to protocol dissectors and file parsers.$$$$$$Display filters can be translated to pcap filters using Edit › Copy › Display filter as pcap filter if each display filter field has a corresponding pcap filter equivalent.$$$$$$Custom columns can be defined using any valid field expression; such as display filter functions; packet slices; arithmetic calculations; logical tests; raw byte addressing; and protocol layer modifiers.$$$$$$Custom output fields for tshark -e can also be defined using any valid field expression.$$$$$$Wireshark can be built with the zlib-ng instead of zlib for compressed file support. Zlib-ng is substantially faster than zlib. The official Windows and macOS packages include this feature.$$$$$$Many other improvements have been made. See the “New and Updated Features” section below for more details.$$$$$$New and Updated Features$$$$$$For more details -Refer https://www.wireshark.org/docs/relnotes/wireshark-4.4.0.html
Wireshark MSI x64 Version 4.2.6.0
What’s New$$$Bug Fixes$$$If you are upgrading Wireshark 4.2.0 or 4.2.1 on Windows you will need to download and install Wireshark 4.2.6 or later by hand.$$$$$$A regression in the TCP Stream Graph Time Sequence (tcptrace) receive window line behavior introduced in 4.2.5 and 4.0.15 has been fixed. Issue 19846$$$$$$The following vulnerability has been fixed:$$$$$$wnpa-sec-2024-10 SPRT dissector crash. Issue 19559.$$$$$$The following bugs have been fixed:$$$$$$RADIUS dissector’s dictionary loading broken in many ways. Issue 6466.$$$$$$3.4 ? 3.6.5 ASCII display is broken on CentOS 7. Issue 18096.$$$$$$Funnel/Lua: Closing child window disconnects buttons of parent. Issue 18386.$$$$$$Lua detection fails with Alpine Linux: missing: LUA_LIBRARIES. Issue 19841.$$$$$$vnd.3gpp.5gnas payloads of type SMS not decoded inside HTTP2 5GC. Issue 19845.$$$$$$TCP Stream Graphs green sliding window line not displayed correctly. Issue 19846.$$$$$$Wireshark window doesn’t fully fit on screen on small resolutions and can’t be resized properly on Russian language. Issue 19861.$$$$$$Wireshark started from command line doesn’t set gui.fileopen_remembered_dir correctly on Windows. Issue 19891.$$$$$$Wireshark expects wrong length for DHCP Relay Agent Information Source Port Suboption. Issue 19909.$$$$$$SIP P-Access-Network-Info header not correctly decoded. Issue 19917.$$$$$$New and Updated Features$$$There are no new or updated features in this release.$$$$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$DHCP; E.212; MySQL; NAS-5GS; PKT CCC; ProtoBuf; RADIUS; RLC-LTE; RTP; SIP; SPRT; Thrift; and Wi-SUN$$$$$$New and Updated Capture File Support$$$log3gpp$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark EXE x64 Version 4.2.6
What’s New$$$Bug Fixes$$$If you are upgrading Wireshark 4.2.0 or 4.2.1 on Windows you will need to download and install Wireshark 4.2.6 or later by hand.$$$$$$A regression in the TCP Stream Graph Time Sequence (tcptrace) receive window line behavior introduced in 4.2.5 and 4.0.15 has been fixed. Issue 19846$$$$$$The following vulnerability has been fixed:$$$$$$wnpa-sec-2024-10 SPRT dissector crash. Issue 19559.$$$$$$The following bugs have been fixed:$$$$$$RADIUS dissector’s dictionary loading broken in many ways. Issue 6466.$$$$$$3.4 ? 3.6.5 ASCII display is broken on CentOS 7. Issue 18096.$$$$$$Funnel/Lua: Closing child window disconnects buttons of parent. Issue 18386.$$$$$$Lua detection fails with Alpine Linux: missing: LUA_LIBRARIES. Issue 19841.$$$$$$vnd.3gpp.5gnas payloads of type SMS not decoded inside HTTP2 5GC. Issue 19845.$$$$$$TCP Stream Graphs green sliding window line not displayed correctly. Issue 19846.$$$$$$Wireshark window doesn’t fully fit on screen on small resolutions and can’t be resized properly on Russian language. Issue 19861.$$$$$$Wireshark started from command line doesn’t set gui.fileopen_remembered_dir correctly on Windows. Issue 19891.$$$$$$Wireshark expects wrong length for DHCP Relay Agent Information Source Port Suboption. Issue 19909.$$$$$$SIP P-Access-Network-Info header not correctly decoded. Issue 19917.$$$$$$New and Updated Features$$$There are no new or updated features in this release.$$$$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$DHCP; E.212; MySQL; NAS-5GS; PKT CCC; ProtoBuf; RADIUS; RLC-LTE; RTP; SIP; SPRT; Thrift; and Wi-SUN$$$$$$New and Updated Capture File Support$$$log3gpp$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark MSI x64 Version 4.2.6.0
What’s New$$$Bug Fixes$$$If you are upgrading Wireshark 4.2.0 or 4.2.1 on Windows you will need to download and install Wireshark 4.2.6 or later by hand.$$$$$$A regression in the TCP Stream Graph Time Sequence (tcptrace) receive window line behavior introduced in 4.2.5 and 4.0.15 has been fixed. Issue 19846$$$$$$The following vulnerability has been fixed:$$$$$$wnpa-sec-2024-10 SPRT dissector crash. Issue 19559.$$$$$$The following bugs have been fixed:$$$$$$RADIUS dissector’s dictionary loading broken in many ways. Issue 6466.$$$$$$3.4 ? 3.6.5 ASCII display is broken on CentOS 7. Issue 18096.$$$$$$Funnel/Lua: Closing child window disconnects buttons of parent. Issue 18386.$$$$$$Lua detection fails with Alpine Linux: missing: LUA_LIBRARIES. Issue 19841.$$$$$$vnd.3gpp.5gnas payloads of type SMS not decoded inside HTTP2 5GC. Issue 19845.$$$$$$TCP Stream Graphs green sliding window line not displayed correctly. Issue 19846.$$$$$$Wireshark window doesn’t fully fit on screen on small resolutions and can’t be resized properly on Russian language. Issue 19861.$$$$$$Wireshark started from command line doesn’t set gui.fileopen_remembered_dir correctly on Windows. Issue 19891.$$$$$$Wireshark expects wrong length for DHCP Relay Agent Information Source Port Suboption. Issue 19909.$$$$$$SIP P-Access-Network-Info header not correctly decoded. Issue 19917.$$$$$$New and Updated Features$$$There are no new or updated features in this release.$$$$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$DHCP; E.212; MySQL; NAS-5GS; PKT CCC; ProtoBuf; RADIUS; RLC-LTE; RTP; SIP; SPRT; Thrift; and Wi-SUN$$$$$$New and Updated Capture File Support$$$log3gpp$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark EXE x64 Version 4.2.6
What’s New$$$Bug Fixes$$$If you are upgrading Wireshark 4.2.0 or 4.2.1 on Windows you will need to download and install Wireshark 4.2.6 or later by hand.$$$$$$A regression in the TCP Stream Graph Time Sequence (tcptrace) receive window line behavior introduced in 4.2.5 and 4.0.15 has been fixed. Issue 19846$$$$$$The following vulnerability has been fixed:$$$$$$wnpa-sec-2024-10 SPRT dissector crash. Issue 19559.$$$$$$The following bugs have been fixed:$$$$$$RADIUS dissector’s dictionary loading broken in many ways. Issue 6466.$$$$$$3.4 ? 3.6.5 ASCII display is broken on CentOS 7. Issue 18096.$$$$$$Funnel/Lua: Closing child window disconnects buttons of parent. Issue 18386.$$$$$$Lua detection fails with Alpine Linux: missing: LUA_LIBRARIES. Issue 19841.$$$$$$vnd.3gpp.5gnas payloads of type SMS not decoded inside HTTP2 5GC. Issue 19845.$$$$$$TCP Stream Graphs green sliding window line not displayed correctly. Issue 19846.$$$$$$Wireshark window doesn’t fully fit on screen on small resolutions and can’t be resized properly on Russian language. Issue 19861.$$$$$$Wireshark started from command line doesn’t set gui.fileopen_remembered_dir correctly on Windows. Issue 19891.$$$$$$Wireshark expects wrong length for DHCP Relay Agent Information Source Port Suboption. Issue 19909.$$$$$$SIP P-Access-Network-Info header not correctly decoded. Issue 19917.$$$$$$New and Updated Features$$$There are no new or updated features in this release.$$$$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$DHCP; E.212; MySQL; NAS-5GS; PKT CCC; ProtoBuf; RADIUS; RLC-LTE; RTP; SIP; SPRT; Thrift; and Wi-SUN$$$$$$New and Updated Capture File Support$$$log3gpp$$$$$$Updated File Format Decoding Support$$$There is no updated file format support in this release.
Wireshark MSI x86 Version 3.6.24.0
Wireshark 3.6.24 Release Notes$$$What is Wireshark?$$$Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting; analysis; development and education.$$$$$$What’s New$$$This is expected to be the final release of the 3.6 branch.$$$$$$This is also the final release with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779.$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2024-09 The editcap command line utility could crash when injecting secrets while writing multiple files. Issue 19782. CVE-2024-4855.$$$$$$The following bugs have been fixed:$$$$$$Wireshark crashes on exit when using wmem_register_callback in a plugin Issue 19579.
Wireshark EXE x86 Version 3.6.24
Wireshark 3.6.24 Release Notes$$$What is Wireshark?$$$Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting; analysis; development and education.$$$$$$What’s New$$$This is expected to be the final release of the 3.6 branch.$$$$$$This is also the final release with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779.$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2024-09 The editcap command line utility could crash when injecting secrets while writing multiple files. Issue 19782. CVE-2024-4855.$$$$$$The following bugs have been fixed:$$$$$$Wireshark crashes on exit when using wmem_register_callback in a plugin Issue 19579.
Wireshark MSI x86 Version 3.6.24.0
Wireshark 3.6.24 Release Notes$$$What is Wireshark?$$$Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting; analysis; development and education.$$$$$$What’s New$$$This is expected to be the final release of the 3.6 branch.$$$$$$This is also the final release with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779.$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2024-09 The editcap command line utility could crash when injecting secrets while writing multiple files. Issue 19782. CVE-2024-4855.$$$$$$The following bugs have been fixed:$$$$$$Wireshark crashes on exit when using wmem_register_callback in a plugin Issue 19579.
Wireshark EXE x86 Version 3.6.24
Wireshark 3.6.24 Release Notes$$$What is Wireshark?$$$Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting; analysis; development and education.$$$$$$What’s New$$$This is expected to be the final release of the 3.6 branch.$$$$$$This is also the final release with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779.$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2024-09 The editcap command line utility could crash when injecting secrets while writing multiple files. Issue 19782. CVE-2024-4855.$$$$$$The following bugs have been fixed:$$$$$$Wireshark crashes on exit when using wmem_register_callback in a plugin Issue 19579.
Wireshark MSI x86 Version 3.6.23.0
What’s New$$$This is expected to be the final release of the 3.6 branch.$$$$$$This is also the final release with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779.$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2024-07 MONGO and ZigBee TLV dissector infinite loops. Issue 19726. CVE-2024-4854.$$$$$$wnpa-sec-2024-08 The editcap command line utility could crash when chopping bytes from the beginning of a packet. Issue 19724. CVE-2024-4853.$$$$$$The following bugs have been fixed:$$$$$$Flow Graph scrolls in the wrong direction vertically when pressing Up/Down Issue 12932.$$$$$$TCP Stream Window Scaling not working in version 2.6.1 and later Issue 15016.$$$$$$TCP stream graphs (Window scaling) axis display is confusing Issue 17425.$$$$$$LUA get_dissector does not give the correct dissector under 32-bit version Issue 18367.$$$$$$Lua: Segfault when registering a field or expert info twice Issue 19194.$$$$$$RTP Player triggers c
Wireshark EXE x86 Version 3.6.23
What’s New$$$This is expected to be the final release of the 3.6 branch.$$$$$$This is also the final release with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779.$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2024-07 MONGO and ZigBee TLV dissector infinite loops. Issue 19726. CVE-2024-4854.$$$$$$wnpa-sec-2024-08 The editcap command line utility could crash when chopping bytes from the beginning of a packet. Issue 19724. CVE-2024-4853.
Wireshark MSI x86 Version 3.6.23.0
What’s New$$$This is expected to be the final release of the 3.6 branch.$$$$$$This is also the final release with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779.$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2024-07 MONGO and ZigBee TLV dissector infinite loops. Issue 19726. CVE-2024-4854.$$$$$$wnpa-sec-2024-08 The editcap command line utility could crash when chopping bytes from the beginning of a packet. Issue 19724. CVE-2024-4853.$$$$$$The following bugs have been fixed:$$$$$$Flow Graph scrolls in the wrong direction vertically when pressing Up/Down Issue 12932.$$$$$$TCP Stream Window Scaling not working in version 2.6.1 and later Issue 15016.$$$$$$TCP stream graphs (Window scaling) axis display is confusing Issue 17425.$$$$$$LUA get_dissector does not give the correct dissector under 32-bit version Issue 18367.$$$$$$Lua: Segfault when registering a field or expert info twice Issue 19194.$$$$$$RTP Player triggers c
Wireshark EXE x86 Version 3.6.23
What’s New$$$This is expected to be the final release of the 3.6 branch.$$$$$$This is also the final release with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779.$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2024-07 MONGO and ZigBee TLV dissector infinite loops. Issue 19726. CVE-2024-4854.$$$$$$wnpa-sec-2024-08 The editcap command line utility could crash when chopping bytes from the beginning of a packet. Issue 19724. CVE-2024-4853.
Wireshark MSI x64 Version 4.2.5.0
What’s New$$$Bug Fixes$$$If you are upgrading Wireshark 4.2.0 or 4.2.1 on Windows you will need to download and install Wireshark 4.2.5 or later by hand.$$$$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2024-07 MONGO and ZigBee TLV dissector infinite loops. Issue 19726. CVE-2024-4854.$$$$$$wnpa-sec-2024-08 The editcap command line utility could crash when chopping bytes from the beginning of a packet. Issue 19724. CVE-2024-4853.$$$$$$wnpa-sec-2024-09 The editcap command line utility could crash when injecting secrets while writing multiple files. Issue 19782. CVE-2024-4855.
Wireshark EXE x64 Version 4.2.5
What’s New$$$Bug Fixes$$$If you are upgrading Wireshark 4.2.0 or 4.2.1 on Windows you will need to download and install Wireshark 4.2.5 or later by hand.$$$$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2024-07 MONGO and ZigBee TLV dissector infinite loops. Issue 19726. CVE-2024-4854.$$$$$$wnpa-sec-2024-08 The editcap command line utility could crash when chopping bytes from the beginning of a packet. Issue 19724. CVE-2024-4853.$$$$$$wnpa-sec-2024-09 The editcap command line utility could crash when injecting secrets while writing multiple files. Issue 19782. CVE-2024-4855.
Wireshark MSI x64 Version 4.2.5.0
What’s New$$$Bug Fixes$$$If you are upgrading Wireshark 4.2.0 or 4.2.1 on Windows you will need to download and install Wireshark 4.2.5 or later by hand.$$$$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2024-07 MONGO and ZigBee TLV dissector infinite loops. Issue 19726. CVE-2024-4854.$$$$$$wnpa-sec-2024-08 The editcap command line utility could crash when chopping bytes from the beginning of a packet. Issue 19724. CVE-2024-4853.$$$$$$wnpa-sec-2024-09 The editcap command line utility could crash when injecting secrets while writing multiple files. Issue 19782. CVE-2024-4855.
Wireshark EXE x64 Version 4.2.5
What’s New$$$Bug Fixes$$$If you are upgrading Wireshark 4.2.0 or 4.2.1 on Windows you will need to download and install Wireshark 4.2.5 or later by hand.$$$$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2024-07 MONGO and ZigBee TLV dissector infinite loops. Issue 19726. CVE-2024-4854.$$$$$$wnpa-sec-2024-08 The editcap command line utility could crash when chopping bytes from the beginning of a packet. Issue 19724. CVE-2024-4853.$$$$$$wnpa-sec-2024-09 The editcap command line utility could crash when injecting secrets while writing multiple files. Issue 19782. CVE-2024-4855.
Wireshark MSI x64 Version 4.2.4.0
Refer - https://www.wireshark.org/docs/relnotes/wireshark-4.2.4.html
Wireshark EXE x64 Version 4.2.4
Refer- https://www.wireshark.org/docs/relnotes/wireshark-4.2.4.html
Wireshark MSI x64 Version 4.2.4.0
Refer - https://www.wireshark.org/docs/relnotes/wireshark-4.2.4.html
Wireshark EXE x64 Version 4.2.4
Refer- https://www.wireshark.org/docs/relnotes/wireshark-4.2.4.html
Wireshark MSI x86 Version 3.6.21.0
Refer - https://www.wireshark.org/docs/relnotes/wireshark-3.6.21.html
Wireshark MSI x64 Version 4.2.3.0
Refer - https://www.wireshark.org/docs/relnotes/wireshark-4.2.3.html
Wireshark EXE x86 Version 3.6.21
Refer - https://www.wireshark.org/docs/relnotes/wireshark-3.6.21.html
Wireshark EXE x64 Version 4.2.3
Refer- https://www.wireshark.org/docs/relnotes/wireshark-4.2.3.html
Wireshark MSI x64 Version 4.2.2.0
Refer - https://www.wireshark.org/docs/relnotes/wireshark-4.2.2.html
Wireshark EXE x64 Version 4.2.2
Refer- https://www.wireshark.org/docs/relnotes/wireshark-4.2.2.html
Wireshark MSI x86 Version 3.6.20.0
Wireshark 3.6.20 Release Notes$$$What is Wireshark?$$$Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting; analysis; development and education.$$$$$$What’s New$$$This is the last release branch with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779$$$$$$If you’re running Wireshark on macOS and upgraded to macOS 13 from an earlier version; you might have to open and run the “Uninstall ChmodBPF” package; then open and run “Install ChmodBPF” in order to reset the ChmodBPF Launch Daemon. Issue 18734.$$$$$$Bug Fixes$$$wnpa-sec-2024-01 GVCP dissector crash. Issue 19496. CVE-2024-0208.$$$$$$wnpa-sec-2024-02 IEEE 1609.2 dissector crash. Issue 19501. CVE-2024-0209.$$$$$$The following bugs have been fixed:$$$$$$Capture filters not saved to recently used list Issue 12918.$$$$$$Segfault when enabling monitor mode on wireless card that falsely claims to support it Issue 16693.$$$$$$Capture filter compilation fails with obscure error message Issue 19480.$$$$$$NFLOG timestamp is incorrect Issue 19525.$$$$$$Qt6 Crash (Double Free) When Attempting to Save TCP Stream Graph Issue 19529.$$$$$$New and Updated Features$$$There are no new or updated features in this release.$$$$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$pcapng: the if_tsoffset option is now supported.$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.
Wireshark EXE x86 Version 3.6.20
Wireshark 3.6.20 Release Notes$$$What is Wireshark?$$$Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting; analysis; development and education.$$$$$$What’s New$$$This is the last release branch with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779$$$$$$If you’re running Wireshark on macOS and upgraded to macOS 13 from an earlier version; you might have to open and run the “Uninstall ChmodBPF” package; then open and run “Install ChmodBPF” in order to reset the ChmodBPF Launch Daemon. Issue 18734.$$$$$$Bug Fixes$$$wnpa-sec-2024-01 GVCP dissector crash. Issue 19496. CVE-2024-0208.$$$$$$wnpa-sec-2024-02 IEEE 1609.2 dissector crash. Issue 19501. CVE-2024-0209.$$$$$$The following bugs have been fixed:$$$$$$Capture filters not saved to recently used list Issue 12918.$$$$$$Segfault when enabling monitor mode on wireless card that falsely claims to support it Issue 16693.$$$$$$Capture filter compilation fails with obscure error message Issue 19480.$$$$$$NFLOG timestamp is incorrect Issue 19525.$$$$$$Qt6 Crash (Double Free) When Attempting to Save TCP Stream Graph Issue 19529.$$$$$$New and Updated Features$$$There are no new or updated features in this release.$$$$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$pcapng: the if_tsoffset option is now supported.$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.
Wireshark EXE x64 Version 4.2.0
Refer- https://www.wireshark.org/docs/relnotes/wireshark-4.2.0.html
Wireshark MSI x64 Version 4.2.0.0
Refer - https://www.wireshark.org/docs/relnotes/wireshark-4.2.0.html
Wireshark EXE x86 Version 3.6.19
Wireshark 3.6.19 Release Notes$$$What is Wireshark?$$$Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting; analysis; development and education.$$$$$$What’s New$$$This is the last release branch with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779$$$$$$If you’re running Wireshark on macOS and upgraded to macOS 13 from an earlier version; you might have to open and run the “Uninstall ChmodBPF” package; then open and run “Install ChmodBPF” in order to reset the ChmodBPF Launch Daemon. Issue 18734.$$$$$$Bug Fixes$$$wnpa-sec-2023-29 NetScreen file parser crash. Issue 19404.$$$$$$The following bugs have been fixed:$$$$$$First ZigBee APS packet is not decrypted Issue 16507.$$$$$$Problem with decoding OpenFlow actions in OFPT_FLOW_MOD message Issue 17072.$$$$$$The frames method in sharkd does not consider time references and displays incorrect delta time Issue 17923.$$$$$$Wireshark interprets If_fcslen option in the Interface Description Block as byte instead of bit. Issue 19174.$$$$$$Flathub’s Wireshark page shows wrong version number Issue 19382.$$$$$$OSPFv3 RI decode error Issue 19444.$$$$$$GSM SIM READ / UPDATE BINARY command has wrong offset Issue 19472.$$$$$$New and Updated Features$$$There are no new or updated features in this release.$$$$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$DHCP; GSM SIM; ISO 15765; OpenFlow v1; and OSPF$$$$$$New and Updated Capture File Support$$$NetScreen and pcapng$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.
Wireshark MSI x86 Version 3.6.19.0
Wireshark 3.6.19 Release Notes$$$What is Wireshark?$$$Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting; analysis; development and education.$$$$$$What’s New$$$This is the last release branch with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779$$$$$$If you’re running Wireshark on macOS and upgraded to macOS 13 from an earlier version; you might have to open and run the “Uninstall ChmodBPF” package; then open and run “Install ChmodBPF” in order to reset the ChmodBPF Launch Daemon. Issue 18734.$$$$$$Bug Fixes$$$wnpa-sec-2023-29 NetScreen file parser crash. Issue 19404.$$$$$$The following bugs have been fixed:$$$$$$First ZigBee APS packet is not decrypted Issue 16507.$$$$$$Problem with decoding OpenFlow actions in OFPT_FLOW_MOD message Issue 17072.$$$$$$The frames method in sharkd does not consider time references and displays incorrect delta time Issue 17923.$$$$$$Wireshark interprets If_fcslen option in the Interface Description Block as byte instead of bit. Issue 19174.$$$$$$Flathub’s Wireshark page shows wrong version number Issue 19382.$$$$$$OSPFv3 RI decode error Issue 19444.$$$$$$GSM SIM READ / UPDATE BINARY command has wrong offset Issue 19472.$$$$$$New and Updated Features$$$There are no new or updated features in this release.$$$$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$DHCP; GSM SIM; ISO 15765; OpenFlow v1; and OSPF$$$$$$New and Updated Capture File Support$$$NetScreen and pcapng$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.
Wireshark EXE x64 Version 4.2.0
Refer- https://www.wireshark.org/docs/relnotes/wireshark-4.2.0.html
Wireshark MSI x64 Version 4.2.0.0
Refer - https://www.wireshark.org/docs/relnotes/wireshark-4.2.0.html
Wireshark EXE x86 Version 3.6.16
What’s New$$$This is the last release branch with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779$$$$$$If you’re running Wireshark on macOS and upgraded to macOS 13 from an earlier version; you might have to open and run the “Uninstall ChmodBPF” package; then open and run “Install ChmodBPF” in order to reset the ChmodBPF Launch Daemon. Issue 18734.$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2023-22 iSCSI dissector crash. Issue 19164. CVE-2023-3649.$$$$$$wnpa-sec-2023-24 BT SDP dissector infinite loop. Issue 19258.$$$$$$wnpa-sec-2023-25 BT SDP dissector memory leak. Issue 19259.$$$$$$wnpa-sec-2023-26 CP2179 dissector crash. Issue 19229.$$$$$$The following bugs have been fixed:$$$$$$Wireshark wrongly blames group membership when pcap capabilities are removed. Issue 18279.$$$$$$Packet bytes window broken layout. Issue 18326.$$$$$$Valid Ethernet CFM DMM packets are shown as malformed. Issue 19198.$$$$$$The QUIC dissector is reporting the quic_transport_parameters max_ack_delay with the title GREASE. Issue 19209.$$$$$$Preferences: Folder name editing behaves weirdly; cursor jumps. Issue 19213.$$$$$$DHCPFO: Expert info list does not show all expert infos. Issue 19216.$$$$$$Applying color filtering fails when selecting the same field to color (i.e.; changing frames without focusing in packet details). Issue 19249.$$$$$$NAS 5GS Malformed Packet Decoding SOR transparent container PLMN ID and access technology list. Issue 19273.$$$$$$New and Updated Features$$$There are no new or updated features in this release.$$$$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$BT SDP; CP2179; CQL; DHCPFO; F1AP; GSM DTAP; IEEE 802.11; NAS-5GS; PFCP; and TFTP$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.
Wireshark MSI x86 Version 3.6.16.0
What’s New$$$This is the last release branch with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779$$$$$$If you’re running Wireshark on macOS and upgraded to macOS 13 from an earlier version; you might have to open and run the “Uninstall ChmodBPF” package; then open and run “Install ChmodBPF” in order to reset the ChmodBPF Launch Daemon. Issue 18734.$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2023-22 iSCSI dissector crash. Issue 19164. CVE-2023-3649.$$$$$$wnpa-sec-2023-24 BT SDP dissector infinite loop. Issue 19258.$$$$$$wnpa-sec-2023-25 BT SDP dissector memory leak. Issue 19259.$$$$$$wnpa-sec-2023-26 CP2179 dissector crash. Issue 19229.$$$$$$The following bugs have been fixed:$$$$$$Wireshark wrongly blames group membership when pcap capabilities are removed. Issue 18279.$$$$$$Packet bytes window broken layout. Issue 18326.$$$$$$Valid Ethernet CFM DMM packets are shown as malformed. Issue 19198.$$$$$$The QUIC dissector is reporting the quic_transport_parameters max_ack_delay with the title GREASE. Issue 19209.$$$$$$Preferences: Folder name editing behaves weirdly; cursor jumps. Issue 19213.$$$$$$DHCPFO: Expert info list does not show all expert infos. Issue 19216.$$$$$$Applying color filtering fails when selecting the same field to color (i.e.; changing frames without focusing in packet details). Issue 19249.$$$$$$NAS 5GS Malformed Packet Decoding SOR transparent container PLMN ID and access technology list. Issue 19273.$$$$$$New and Updated Features$$$There are no new or updated features in this release.$$$$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$BT SDP; CP2179; CQL; DHCPFO; F1AP; GSM DTAP; IEEE 802.11; NAS-5GS; PFCP; and TFTP$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.
Wireshark EXE x64 Version 4.0.8
What’s New$$$We do not ship official 32-bit Windows packages for Wireshark 4.0 and later. If you need to use Wireshark on that platform; we recommend using the latest 3.6 release. Issue 17779$$$$$$If you’re running Wireshark on macOS and upgraded to macOS 13 from an earlier version; you might have to open and run the “Uninstall ChmodBPF” package; then open and run “Install ChmodBPF” in order to reset the ChmodBPF Launch Daemon. Issue 18734.$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2023-23 CBOR dissector crash. Issue 19144.$$$$$$wnpa-sec-2023-24 BT SDP dissector infinite loop. Issue 19258.$$$$$$wnpa-sec-2023-25 BT SDP dissector memory leak. Issue 19259.$$$$$$wnpa-sec-2023-26 CP2179 dissector crash. Issue 19229.$$$$$$The following bugs have been fixed:$$$$$$TShark cannot capture to pipe on Windows correctly. Issue 17900.$$$$$$Wireshark wrongly blames group membership when pcap capabilities are removed. Issue 18279.$$$$$$Packet bytes window broken layout. Issue 18326.$$$$$$RTP Player only shows waveform until sequence rollover. Issue 18829.$$$$$$Valid Ethernet CFM DMM packets are shown as malformed. Issue 19198.$$$$$$Crash on DICOM Export Objects window close. Issue 19207.$$$$$$The QUIC dissector is reporting the quic_transport_parameters max_ack_delay with the title \GREASE\ Issue 19209.$$$$$$Preferences: Folder name editing behaves weirdly; cursor jumps. Issue 19213.$$$$$$DHCPFO: Expert info list does not show all expert infos. Issue 19216.$$$$$$Websocket packets not decoded and displayed for Field type=Custom and Field name websocket.payload.text. Issue 19220.$$$$$$Cannot read pcapng file captured on OpenBSD and read on FreeBSD. Issue 19230.$$$$$$UI: While capturing the Wireshark icon changes from green to blue when new file is created. Issue 19252.$$$$$$Conversation: heap-use-after-free after wmem_leave_file_scope. Issue 19265.$$$$$$IP Packets with DSCP 44 does not indicate Voice-Admit Issue 19270.$$$$$$NAS 5GS Malformed Packet Decoding SOR transparent container PLMN ID and access technology list. Issue 19273.$$$$$$UI: Auto scroll button in the toolbar is turned on when manually scrolling to the end of packet list. Issue 19274.$$$$$$New and Updated Features$$$There are no new or updated features in this release.$$$$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$BT SDP; CBOR; CFM; CP2179; CQL; DHCPFO; DICOM; F1AP; GSM DTAP; IEEE 802.11; IPv4; NAS-5GS; PFCP; PKT CCC; QUIC; RTP; TFTP; WebSocket; and XnAP$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.
Wireshark MSI x64 Version 4.0.8.0
What’s New$$$We do not ship official 32-bit Windows packages for Wireshark 4.0 and later. If you need to use Wireshark on that platform; we recommend using the latest 3.6 release. Issue 17779$$$$$$If you’re running Wireshark on macOS and upgraded to macOS 13 from an earlier version; you might have to open and run the “Uninstall ChmodBPF” package; then open and run “Install ChmodBPF” in order to reset the ChmodBPF Launch Daemon. Issue 18734.$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2023-23 CBOR dissector crash. Issue 19144.$$$$$$wnpa-sec-2023-24 BT SDP dissector infinite loop. Issue 19258.$$$$$$wnpa-sec-2023-25 BT SDP dissector memory leak. Issue 19259.$$$$$$wnpa-sec-2023-26 CP2179 dissector crash. Issue 19229.$$$$$$The following bugs have been fixed:$$$$$$TShark cannot capture to pipe on Windows correctly. Issue 17900.$$$$$$Wireshark wrongly blames group membership when pcap capabilities are removed. Issue 18279.$$$$$$Packet bytes window broken layout. Issue 18326.$$$$$$RTP Player only shows waveform until sequence rollover. Issue 18829.$$$$$$Valid Ethernet CFM DMM packets are shown as malformed. Issue 19198.$$$$$$Crash on DICOM Export Objects window close. Issue 19207.$$$$$$The QUIC dissector is reporting the quic_transport_parameters max_ack_delay with the title \GREASE\ Issue 19209.$$$$$$Preferences: Folder name editing behaves weirdly; cursor jumps. Issue 19213.$$$$$$DHCPFO: Expert info list does not show all expert infos. Issue 19216.$$$$$$Websocket packets not decoded and displayed for Field type=Custom and Field name websocket.payload.text. Issue 19220.$$$$$$Cannot read pcapng file captured on OpenBSD and read on FreeBSD. Issue 19230.$$$$$$UI: While capturing the Wireshark icon changes from green to blue when new file is created. Issue 19252.$$$$$$Conversation: heap-use-after-free after wmem_leave_file_scope. Issue 19265.$$$$$$IP Packets with DSCP 44 does not indicate Voice-Admit Issue 19270.$$$$$$NAS 5GS Malformed Packet Decoding SOR transparent container PLMN ID and access technology list. Issue 19273.$$$$$$UI: Auto scroll button in the toolbar is turned on when manually scrolling to the end of packet list. Issue 19274.$$$$$$New and Updated Features$$$There are no new or updated features in this release.$$$$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$BT SDP; CBOR; CFM; CP2179; CQL; DHCPFO; DICOM; F1AP; GSM DTAP; IEEE 802.11; IPv4; NAS-5GS; PFCP; PKT CCC; QUIC; RTP; TFTP; WebSocket; and XnAP$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.
Wireshark MSI x86 Version 3.6.15.0
Wireshark 3.6.15 Release Notes$$$What is Wireshark?$$$Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting; analysis; development and education.$$$$$$What’s New$$$This is the last release branch with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779$$$$$$If you’re running Wireshark on macOS and upgraded to macOS 13 from an earlier version; you might have to open and run the “Uninstall ChmodBPF” package; then open and run “Install ChmodBPF” in order to reset the ChmodBPF Launch Daemon. Issue 18734.$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2023-21 Kafka dissector crash. Issue 19105.$$$$$$The following bugs have been fixed:$$$$$$Crash when (re)loading a capture file after renaming a dfilter macro Issue 13753.
Wireshark EXE x86 Version 3.6.15
This is the last release branch with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779$$$$$$If you’re running Wireshark on macOS and upgraded to macOS 13 from an earlier version; you might have to open and run the “Uninstall ChmodBPF” package; then open and run “Install ChmodBPF” in order to reset the ChmodBPF Launch Daemon. Issue 18734.$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2023-21 Kafka dissector crash. Issue 19105.$$$$$$The following bugs have been fixed:$$$$$$Crash when (re)loading a capture file after renaming a dfilter macro Issue 13753.$$$$$$Moving a column deselects selected packet and moves to beginning of packet list Issue 16251.$$$$$$If you set the default interface in the preferences; it doesn’t work with TShark Issue 16593.$$$$$$Severe performance issues in Follow ? Save As raw workflow Issue 17313.$$$$$$NAS-5GS Operator-defined Access Category: Multiple Criteria values not displayed in dissected packet display Issue 18941.$$$$$$CQL protocol parsing issues with Result frames from open source Cassandra Issue 19119.$$$$$$TLS 1.3 second Key Update doesn’t work Issue 19120.
Wireshark EXE x64 Version 4.0.7
What’s New$$$We do not ship official 32-bit Windows packages for Wireshark 4.0 and later. If you need to use Wireshark on that platform; we recommend using the latest 3.6 release. Issue 17779$$$$$$If you’re running Wireshark on macOS and upgraded to macOS 13 from an earlier version; you might have to open and run the “Uninstall ChmodBPF” package; then open and run “Install ChmodBPF” in order to reset the ChmodBPF Launch Daemon. Issue 18734.$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2023-21 Kafka dissector crash. Issue 19105.$$$$$$wnpa-sec-2023-22 iSCSI dissector crash. Issue 19164.$$$$$$The following bugs have been fixed:$$$$$$Crash when (re)loading a capture file after renaming a dfilter macro. Issue 13753.$$$$$$Moving a column deselects selected packet and moves to beginning of packet list. Issue 16251.$$$$$$If you set the default interface in the preferences; it doesn’t work with TShark. Issue 16593.$$$$$$Severe performance issues in Follow ? Save As raw workflow. Issue 17313.
Wireshark MSI x64 Version 4.0.7.0
What’s New$$$We do not ship official 32-bit Windows packages for Wireshark 4.0 and later. If you need to use Wireshark on that platform; we recommend using the latest 3.6 release. Issue 17779$$$$$$If you’re running Wireshark on macOS and upgraded to macOS 13 from an earlier version; you might have to open and run the “Uninstall ChmodBPF” package; then open and run “Install ChmodBPF” in order to reset the ChmodBPF Launch Daemon. Issue 18734.$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2023-21 Kafka dissector crash. Issue 19105.$$$$$$wnpa-sec-2023-22 iSCSI dissector crash. Issue 19164.
Wireshark MSI x86 Version 3.6.14.0
$$$Bug Fixes$$$$$$The following vulnerabilities have been fixed:$$$$$$ wnpa-sec-2023-12 Candump log file parser crash. Issue 19062. CVE-2023-2855.$$$$$$ wnpa-sec-2023-13 BLF file parser crash. Issue 19063. CVE-2023-2857.$$$$$$ wnpa-sec-2023-14 GDSDB dissector infinite loop. Issue 19068.$$$$$$ wnpa-sec-2023-15 NetScaler file parser crash. Issue 19081. CVE-2023-2858.$$$$$$ wnpa-sec-2023-16 VMS TCPIPtrace file parser crash. Issue 19083. CVE-2023-2856.$$$$$$ wnpa-sec-2023-19 IEEE C37.118 Synchrophasor dissector crash. Issue 19087. CVE-2023-0668.$$$$$$ wnpa-sec-2023-20 XRA dissector infinite loop. Issue 19100.$$$$$$The following bugs have been fixed:$$$$$$ Incorrect padding in BFCP decoder Issue 18890.$$$$$$ SPNEGO dissector bug Issue 18991.$$$$$$ SRT values are incorrect when applying a time shift. Issue 18999.$$$$$$ batadv dissector bug Issue 19047.$$$$$$ [UDS] When filtering the uds.wdbi.data_identifier or uds.iocbi.data_identifier field is interpreted as 1 byte whereas it consists of 2 bytes Issue 19078.$$$$$$ Wireshark can’t save this capture in that format Issue 19080.$$$$$$ MSMMS parsing buffer overflow Issue 19086.$$$$$$ USB HID parser shows wrong label for usages Rx/Vx/Vbrx of usage page Generic Desktop Control Issue 19095.$$$$$$ Follow ? QUIC Stream mixes data between streams. Issue 19102.$$$$$$
Wireshark EXE x86 Version 3.6.14
$$$Bug Fixes$$$$$$The following vulnerabilities have been fixed:$$$$$$ wnpa-sec-2023-12 Candump log file parser crash. Issue 19062. CVE-2023-2855.$$$$$$ wnpa-sec-2023-13 BLF file parser crash. Issue 19063. CVE-2023-2857.$$$$$$ wnpa-sec-2023-14 GDSDB dissector infinite loop. Issue 19068.$$$$$$ wnpa-sec-2023-15 NetScaler file parser crash. Issue 19081. CVE-2023-2858.$$$$$$ wnpa-sec-2023-16 VMS TCPIPtrace file parser crash. Issue 19083. CVE-2023-2856.$$$$$$ wnpa-sec-2023-19 IEEE C37.118 Synchrophasor dissector crash. Issue 19087. CVE-2023-0668.$$$$$$ wnpa-sec-2023-20 XRA dissector infinite loop. Issue 19100.$$$$$$The following bugs have been fixed:$$$$$$ Incorrect padding in BFCP decoder Issue 18890.$$$$$$ SPNEGO dissector bug Issue 18991.$$$$$$ SRT values are incorrect when applying a time shift. Issue 18999.$$$$$$ batadv dissector bug Issue 19047.$$$$$$ [UDS] When filtering the uds.wdbi.data_identifier or uds.iocbi.data_identifier field is interpreted as 1 byte whereas it consists of 2 bytes Issue 19078.$$$$$$ Wireshark can’t save this capture in that format Issue 19080.$$$$$$ MSMMS parsing buffer overflow Issue 19086.$$$$$$ USB HID parser shows wrong label for usages Rx/Vx/Vbrx of usage page Generic Desktop Control Issue 19095.$$$$$$ Follow ? QUIC Stream mixes data between streams. Issue 19102.$$$$$$
Wireshark MSI x64 Version 4.0.6.0
$$$Bug Fixes$$$$$$The following vulnerabilities have been fixed:$$$$$$ wnpa-sec-2023-12 Candump log file parser crash. Issue 19062. CVE-2023-2855.$$$$$$ wnpa-sec-2023-13 BLF file parser crash. Issue 19063. CVE-2023-2857.$$$$$$ wnpa-sec-2023-14 GDSDB dissector infinite loop. Issue 19068.$$$$$$ wnpa-sec-2023-15 NetScaler file parser crash. Issue 19081. CVE-2023-2858.$$$$$$ wnpa-sec-2023-16 VMS TCPIPtrace file parser crash. Issue 19083. CVE-2023-2856.$$$$$$ wnpa-sec-2023-17 BLF file parser crash. Issue 19084. CVE-2023-2854.$$$$$$ wnpa-sec-2023-18 RTPS dissector crash. Issue 19085. CVE-2023-0666.$$$$$$ wnpa-sec-2023-19 IEEE C37.118 Synchrophasor dissector crash. Issue 19087. CVE-2023-0668.$$$$$$ wnpa-sec-2023-20 XRA dissector infinite loop. Issue 19100.$$$$$$The following bugs have been fixed:$$$$$$ Conversations list has incorrect unit (bytes) in bit speed columns in the 3.7 development versions. Issue 18211.$$$$$$ The media_type table should treat media types; e.g. application/3gppHal+json; as case-insensitive. Issue 18611.$$$$$$ NNTP dissector bug. Issue 18981.$$$$$$ Incorrect padding in BFCP decoder. Issue 18890.$$$$$$ SPNEGO dissector bug. Issue 18991.$$$$$$ SRT values are incorrect when applying a time shift. Issue 18999.$$$$$$ Add warning that capturing is not supported in Wireshark installed from flatpak. Issue 19008.$$$$$$ Opening Wireshark with -z io;stat option. Issue 19042.$$$$$$ batadv dissector bug. Issue 19047.$$$$$$ radiotap-gen build fails if pcap is not found. Issue 19059.$$$$$$ [UDS] When filtering the uds.wdbi.data_identifier or uds.iocbi.data_identifier field is interpreted as 1 byte whereas it consists of 2 bytes. Issue 19078.$$$$$$ Wireshark can’t save this capture in that format. Issue 19080.$$$$$$ MSMMS parsing buffer overflow. Issue 19086.$$$$$$ USB HID parser shows wrong label for usages Rx/Vx/Vbrx of usage page Generic Desktop Control. Issue 19095.$$$$$$ Follow ? QUIC Stream mixes data between streams. Issue 19102.$$$$$$
Wireshark EXE x64 Version 4.0.6
$$$Bug Fixes$$$$$$The following vulnerabilities have been fixed:$$$$$$ wnpa-sec-2023-12 Candump log file parser crash. Issue 19062. CVE-2023-2855.$$$$$$ wnpa-sec-2023-13 BLF file parser crash. Issue 19063. CVE-2023-2857.$$$$$$ wnpa-sec-2023-14 GDSDB dissector infinite loop. Issue 19068.$$$$$$ wnpa-sec-2023-15 NetScaler file parser crash. Issue 19081. CVE-2023-2858.$$$$$$ wnpa-sec-2023-16 VMS TCPIPtrace file parser crash. Issue 19083. CVE-2023-2856.$$$$$$ wnpa-sec-2023-17 BLF file parser crash. Issue 19084. CVE-2023-2854.$$$$$$ wnpa-sec-2023-18 RTPS dissector crash. Issue 19085. CVE-2023-0666.$$$$$$ wnpa-sec-2023-19 IEEE C37.118 Synchrophasor dissector crash. Issue 19087. CVE-2023-0668.$$$$$$ wnpa-sec-2023-20 XRA dissector infinite loop. Issue 19100.$$$$$$The following bugs have been fixed:$$$$$$ Conversations list has incorrect unit (bytes) in bit speed columns in the 3.7 development versions. Issue 18211.$$$$$$ The media_type table should treat media types; e.g. application/3gppHal+json; as case-insensitive. Issue 18611.$$$$$$ NNTP dissector bug. Issue 18981.$$$$$$ Incorrect padding in BFCP decoder. Issue 18890.$$$$$$ SPNEGO dissector bug. Issue 18991.$$$$$$ SRT values are incorrect when applying a time shift. Issue 18999.$$$$$$ Add warning that capturing is not supported in Wireshark installed from flatpak. Issue 19008.$$$$$$ Opening Wireshark with -z io;stat option. Issue 19042.$$$$$$ batadv dissector bug. Issue 19047.$$$$$$ radiotap-gen build fails if pcap is not found. Issue 19059.$$$$$$ [UDS] When filtering the uds.wdbi.data_identifier or uds.iocbi.data_identifier field is interpreted as 1 byte whereas it consists of 2 bytes. Issue 19078.$$$$$$ Wireshark can’t save this capture in that format. Issue 19080.$$$$$$ MSMMS parsing buffer overflow. Issue 19086.$$$$$$ USB HID parser shows wrong label for usages Rx/Vx/Vbrx of usage page Generic Desktop Control. Issue 19095.$$$$$$ Follow ? QUIC Stream mixes data between streams. Issue 19102.$$$$$$
Wireshark MSI x86 Version 3.6.13.0
Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2023-09 RPCoRDMA dissector crash. Issue 18852. CVE-2023-1992.$$$$$$wnpa-sec-2023-10 LISP dissector large loop. Issue 18900. CVE-2023-1993.$$$$$$wnpa-sec-2023-11 GQUIC dissector crash Issue 18947. CVE-2023-1994.$$$$$$The following bugs have been fixed:$$$$$$Wireshark ITS Dissector RTCMEM wrong protocol version selector 2 - should use 1 Issue 18862.$$$$$$Wireshark treats the letter E in SSRC as an exponential representation of a number Issue 18879.$$$$$$VNC RRE Parser skips over data Issue 18883.$$$$$$Fuzz job crash output: fuzz-2023-03-27-7564.pcap Issue 18934.$$$$$$Fuzz job crash output: fuzz-2023-03-31-6903.pcap Issue 18947.$$$$$$RTP analysis shows incorrect timestamp error when timestamp is rolled over Issue 18973.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$DNS; ERF; FF; genl; GQUIC; GSM A-bis OML; HL7; IEEE 802.11; ITS; ITS; LISP; netlink; netlink-netfilter; netlink-sock_diag; nl80211; RLC; RPCoRDMA; RTPS; SCTP; SMB; VNC; and WCP$$$$$$
Wireshark MSI x64 Version 4.0.5.0
Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2023-09 RPCoRDMA dissector crash. Issue 18852.$$$$$$wnpa-sec-2023-10 LISP dissector large loop. Issue 18900.$$$$$$wnpa-sec-2023-11 GQUIC dissector crash Issue 18947.$$$$$$The following bugs have been fixed:$$$$$$Wireshark ITS Dissector RTCMEM wrong protocol version selector 2 - should use 1. Issue 18862.$$$$$$Wireshark treats the letter E in SSRC as an exponential representation of a number. Issue 18879.$$$$$$VNC RRE Parser skips over data. Issue 18883.$$$$$$sshdump coredump when --remote-interface is left empty. Issue 18904.$$$$$$Fuzz job crash output: fuzz-2023-03-17-7298.pcap. Issue 18917.$$$$$$Fuzz job crash output: fuzz-2023-03-27-7564.pcap. Issue 18934.$$$$$$RFC8925 support (dhcp option 108) Issue 18943.$$$$$$DIS dissector shows an incorrect state in the packet list info column. Issue 18967.$$$$$$RTP analysis shows incorrect timestamp error when timestamp is rolled over. Issue 18973.$$$$$$Asterisk (*) key crash on Endpoint/Conversation dialog. Issue 18975.$$$$$$The RTP player waveform now synchronizes better with audio.
Wireshark EXE x86 Version 3.6.13
Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2023-09 RPCoRDMA dissector crash. Issue 18852. CVE-2023-1992.$$$$$$wnpa-sec-2023-10 LISP dissector large loop. Issue 18900. CVE-2023-1993.$$$$$$wnpa-sec-2023-11 GQUIC dissector crash Issue 18947. CVE-2023-1994.$$$$$$The following bugs have been fixed:$$$$$$Wireshark ITS Dissector RTCMEM wrong protocol version selector 2 - should use 1 Issue 18862.$$$$$$Wireshark treats the letter E in SSRC as an exponential representation of a number Issue 18879.$$$$$$VNC RRE Parser skips over data Issue 18883.$$$$$$Fuzz job crash output: fuzz-2023-03-27-7564.pcap Issue 18934.$$$$$$Fuzz job crash output: fuzz-2023-03-31-6903.pcap Issue 18947.$$$$$$RTP analysis shows incorrect timestamp error when timestamp is rolled over Issue 18973.
Wireshark EXE x64 Version 4.0.5
Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2023-09 RPCoRDMA dissector crash. Issue 18852.$$$$$$wnpa-sec-2023-10 LISP dissector large loop. Issue 18900.$$$$$$wnpa-sec-2023-11 GQUIC dissector crash Issue 18947.$$$$$$The following bugs have been fixed:$$$$$$Wireshark ITS Dissector RTCMEM wrong protocol version selector 2 - should use 1. Issue 18862.$$$$$$Wireshark treats the letter E in SSRC as an exponential representation of a number. Issue 18879.$$$$$$VNC RRE Parser skips over data. Issue 18883.$$$$$$sshdump coredump when --remote-interface is left empty. Issue 18904.$$$$$$Fuzz job crash output: fuzz-2023-03-17-7298.pcap. Issue 18917.$$$$$$Fuzz job crash output: fuzz-2023-03-27-7564.pcap. Issue 18934.$$$$$$RFC8925 support (dhcp option 108) Issue 18943.$$$$$$DIS dissector shows an incorrect state in the packet list info column. Issue 18967.$$$$$$RTP analysis shows incorrect timestamp error when timestamp is rolled over. Issue 18973.$$$$$$Asterisk (*) key crash on Endpoint/Conversation dialog. Issue 18975.$$$$$$The RTP player waveform now synchronizes better with audio.
Wireshark MSI x86 Version 3.6.12.0
What’s New$$$This is the last release branch with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2023-08 ISO 15765 and ISO 10681 dissector crash. Issue 18839.$$$$$$The following bugs have been fixed:$$$$$$UTF-8 characters end up escaped in PSML output Issue 10445.$$$$$$Export filtered displayed packets won’t save IP fragments of SCTP fragments needed to reassemble a displayed frame. Issue 12597.$$$$$$The intelligent scroll bar or minimap is not predictable on locating and scrolling Issue 13989.$$$$$$If you mark (or unmark) the currently-selected frame; the packet details still say it’s not marked (or it is marked) Issue 14330.$$$$$$Sorting Packet Loss Column is not sorting correct Issue 16785.$$$$$$SIP TCP decoding regression from Wireshark 1.99.0 to 3.6.8 Issue 18411.$$$$$$ChmodBPF not working on macOS Ventura 13.1 Issue 18734.$$$$$$Symbolic links to packages in macOS dmg can’t be double-clicked to install on macOS 13.2 Issue 18830.$$$$$$Potential memory leak in tshark.c Issue 18837.$$$$$$Fuzz job crash output: fuzz-2023-02-05-7303.pcap Issue 18842.$$$$$$f5fileinfo: Hardware platforms missing descriptions Issue 18848.$$$$$$The lines in the intelligent scrollbar are off by one Issue 18850.$$$$$$TECMP dissector shows the wrong Voltage in Vendor Data Issue 18871.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$DHCP; ERF; F5 Ethernet trailer; GMR-1 RR; Gryphon; GSM SMS; H.450; ISO 10681; ISO 15765; NAS-5GS; NR RRC; NS Trace; OptoMMP; PDCP-LTE; QSIG; ROHC; RSVP; RTCP; SCTP; SIP; TCP; TECMP; TWAMP; and UMTS RLC$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.
Wireshark EXE x86 Version 3.6.12
What’s New$$$This is the last release branch with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2023-08 ISO 15765 and ISO 10681 dissector crash. Issue 18839.$$$$$$The following bugs have been fixed:$$$$$$UTF-8 characters end up escaped in PSML output Issue 10445.$$$$$$Export filtered displayed packets won’t save IP fragments of SCTP fragments needed to reassemble a displayed frame. Issue 12597.$$$$$$The intelligent scroll bar or minimap is not predictable on locating and scrolling Issue 13989.$$$$$$If you mark (or unmark) the currently-selected frame; the packet details still say it’s not marked (or it is marked) Issue 14330.$$$$$$Sorting Packet Loss Column is not sorting correct Issue 16785.$$$$$$SIP TCP decoding regression from Wireshark 1.99.0 to 3.6.8 Issue 18411.$$$$$$ChmodBPF not working on macOS Ventura 13.1 Issue 18734.$$$$$$Symbolic links to packages in macOS dmg can’t be double-clicked to install on macOS 13.2 Issue 18830.$$$$$$Potential memory leak in tshark.c Issue 18837.$$$$$$Fuzz job crash output: fuzz-2023-02-05-7303.pcap Issue 18842.$$$$$$f5fileinfo: Hardware platforms missing descriptions Issue 18848.$$$$$$The lines in the intelligent scrollbar are off by one Issue 18850.$$$$$$TECMP dissector shows the wrong Voltage in Vendor Data Issue 18871.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$DHCP; ERF; F5 Ethernet trailer; GMR-1 RR; Gryphon; GSM SMS; H.450; ISO 10681; ISO 15765; NAS-5GS; NR RRC; NS Trace; OptoMMP; PDCP-LTE; QSIG; ROHC; RSVP; RTCP; SCTP; SIP; TCP; TECMP; TWAMP; and UMTS RLC$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.
Wireshark MSI x64 Version 4.0.4.0
Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2023-08 ISO 15765 and ISO 10681 dissector crash. Issue 18839.$$$$$$The following bugs have been fixed:$$$$$$UTF-8 characters end up escaped in PSML output. Issue 10445.$$$$$$Export filtered displayed packets won’t save IP fragments of SCTP fragments needed to reassemble a displayed frame. Issue 12597.$$$$$$DICOM dissection in reassembled PDV goes wrong. Issue 13388.$$$$$$Export Objects - IMF produces incorrect file; TCP reassembly fails with retransmissions that have additional data. Issue 13523.$$$$$$The intelligent scroll bar or minimap is not predictable on locating and scrolling. Issue 13989.$$$$$$If you mark (or unmark) the currently-selected frame; the packet details still say it’s not marked (or it is marked) Issue 14330.$$$$$$An out-of-order packet incorrectly detected as retransmission breaks desegmentation of TCP stream. Issue 15993.$$$$$$Sorting Packet Loss Column is not sorting correct. Issue 16785.$$$$$$Some HTTPS packets cannot be decrypted. Issue 17406.$$$$$$SIP TCP decoding regression from Wireshark 1.99.0 to 3.6.8. Issue 18411.$$$$$$Frame comments not preserved when using filter to write new pcap from tshark. Issue 18693.$$$$$$ChmodBPF not working on macOS Ventura 13.1. Issue 18734.$$$$$$Wireshark GUI and window manager stuck after setting display filter. Issue 18809.$$$$$$Dissector bug; protocol H.261. Issue 18812.$$$$$$File extension heuristics are case-sensitive. Issue 18821.$$$$$$Symbolic links to packages in macOS dmg can’t be double-clicked to install on macOS 13.2. Issue 18830.$$$$$$Potential memory leak in tshark.c. Issue 18837.$$$$$$Fuzz job crash output: fuzz-2023-02-05-7303.pcap. Issue 18842.$$$$$$f5fileinfo: Hardware platforms missing descriptions. Issue 18848.$$$$$$The lines in the intelligent scrollbar are off by one. Issue 18850.$$$$$$Wireshark crashes on invalid UDS packet in Lua context. Issue 18865.$$$$$$TECMP dissector shows the wrong Voltage in Vendor Data. Issue 18871.$$$$$$UDS: Names of RDTCI subfunctions 0x0b …? 0x0e are not correct. Issue 18873.$$$$$$New and Updated Features$$$There are no new or updated features in this release.$$$$$$Removed Features and Support$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$ASTERIX; BGP; DHCP; ERF; F5 Ethernet trailer; GMR-1 RR; Gryphon; GSM SMS; H.261; H.450; ISO 10681; ISO 15765; MIPv6; NAS-5gs; NR RRC; NS Trace; OptoMMP; PDCP-LTE; PDCP-NR; QSIG; ROHC; RSVP; RTCP; SCTP; SIP; TCP; TECMP; TWAMP; UDS; and UMTS RLC$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.
Wireshark EXE x64 Version 4.0.4
Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2023-08 ISO 15765 and ISO 10681 dissector crash. Issue 18839.$$$$$$The following bugs have been fixed:$$$$$$UTF-8 characters end up escaped in PSML output. Issue 10445.$$$$$$Export filtered displayed packets won’t save IP fragments of SCTP fragments needed to reassemble a displayed frame. Issue 12597.$$$$$$DICOM dissection in reassembled PDV goes wrong. Issue 13388.$$$$$$Export Objects - IMF produces incorrect file; TCP reassembly fails with retransmissions that have additional data. Issue 13523.$$$$$$The intelligent scroll bar or minimap is not predictable on locating and scrolling. Issue 13989.$$$$$$If you mark (or unmark) the currently-selected frame; the packet details still say it’s not marked (or it is marked) Issue 14330.$$$$$$An out-of-order packet incorrectly detected as retransmission breaks desegmentation of TCP stream. Issue 15993.$$$$$$Sorting Packet Loss Column is not sorting correct. Issue 16785.$$$$$$Some HTTPS packets cannot be decrypted. Issue 17406.$$$$$$SIP TCP decoding regression from Wireshark 1.99.0 to 3.6.8. Issue 18411.$$$$$$Frame comments not preserved when using filter to write new pcap from tshark. Issue 18693.$$$$$$ChmodBPF not working on macOS Ventura 13.1. Issue 18734.$$$$$$Wireshark GUI and window manager stuck after setting display filter. Issue 18809.$$$$$$Dissector bug; protocol H.261. Issue 18812.$$$$$$File extension heuristics are case-sensitive. Issue 18821.$$$$$$Symbolic links to packages in macOS dmg can’t be double-clicked to install on macOS 13.2. Issue 18830.$$$$$$Potential memory leak in tshark.c. Issue 18837.$$$$$$Fuzz job crash output: fuzz-2023-02-05-7303.pcap. Issue 18842.$$$$$$f5fileinfo: Hardware platforms missing descriptions. Issue 18848.$$$$$$The lines in the intelligent scrollbar are off by one. Issue 18850.$$$$$$Wireshark crashes on invalid UDS packet in Lua context. Issue 18865.$$$$$$TECMP dissector shows the wrong Voltage in Vendor Data. Issue 18871.$$$$$$UDS: Names of RDTCI subfunctions 0x0b …? 0x0e are not correct. Issue 18873.$$$$$$New and Updated Features$$$There are no new or updated features in this release.$$$$$$Removed Features and Support$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$ASTERIX; BGP; DHCP; ERF; F5 Ethernet trailer; GMR-1 RR; Gryphon; GSM SMS; H.261; H.450; ISO 10681; ISO 15765; MIPv6; NAS-5gs; NR RRC; NS Trace; OptoMMP; PDCP-LTE; PDCP-NR; QSIG; ROHC; RSVP; RTCP; SCTP; SIP; TCP; TECMP; TWAMP; UDS; and UMTS RLC$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.
Wireshark MSI x86 Version 3.6.11.0
Wireshark 3.6.11 Release Notes$$$What is Wireshark?$$$Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting; analysis; development and education.$$$$$$What’s New$$$This is the last release branch with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2023-02 NFS dissector memory leak. Issue 18628.$$$$$$wnpa-sec-2023-03 Dissection engine crash. Issue 18766.$$$$$$wnpa-sec-2023-04 GNW dissector crash. Issue 18779.$$$$$$wnpa-sec-2023-05 iSCSI dissector crash. Issue 18796.$$$$$$wnpa-sec-2023-06 Multiple dissector excessive loops. Issue 18711. Issue 18720; Issue 18737.$$$$$$wnpa-sec-2023-07 TIPC dissector crash. Issue 18770.$$$$$$The following bugs have been fixed:$$$$$$Qt: After modifying coloring rules; the coloring rule applied to the first packet reflects the coloring rules previously in effect. Issue 12475.$$$$$$Help file doesn’t display for extcap interfaces Issue 15592.$$$$$$Dissector bug; protocol DRBD Issue 16689.$$$$$$For USB traffic on XHC20 interface destination is always given as Host Issue 16768.$$$$$$Wrong pointer conversion in get_data_source_tvb_by_name() Issue 18517.$$$$$$Wrong number of bits skipped while decoding an empty UTF8String on UPER packet Issue 18702.$$$$$$Uninitialized values in various dissectors Issue 18742.$$$$$$Q.850 - error in label for cause 0x7F Issue 18780.$$$$$$Uninitialized values in CoAP and RTPS dissectors Issue 18785.$$$$$$Screenshots in AppStream metainfo.xml file not available Issue 18801.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$BEEP; BGP; BPv6; BSSGP; CoAP; GNW; GSM A-bis P-GSL; GSM BSSMAP; iSCSI; ISUP; Kafka; LwM2M-TLV; NAS-5GS; NFS; OPUS; RLC; ROHC; RTPS; TCP; Telnet; and USB$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.
Wireshark EXE x64 Version 4.0.3
Wireshark 4.0.3 Release Notes$$$What is Wireshark?$$$Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting; analysis; development and education.$$$$$$What’s New$$$We do not ship official 32-bit Windows packages for Wireshark 4.0 and later. If you need to use Wireshark on that platform; we recommend using the latest 3.6 release. Issue 17779$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2023-01 EAP dissector crash. Issue 18622.$$$$$$wnpa-sec-2023-02 NFS dissector memory leak. Issue 18628.$$$$$$wnpa-sec-2023-03 Dissection engine crash. Issue 18766.$$$$$$wnpa-sec-2023-04 GNW dissector crash. Issue 18779.$$$$$$wnpa-sec-2023-05 iSCSI dissector crash. Issue 18796.$$$$$$wnpa-sec-2023-06 Multiple dissector excessive loops. Issue 18711. Issue 18720; Issue 18737.$$$$$$wnpa-sec-2023-07 TIPC dissector crash. Issue 18770.$$$$$$The following bugs have been fixed:$$$$$$Qt: After modifying coloring rules; the coloring rule applied to the first packet reflects the coloring rules previously in effect. Issue 12475.$$$$$$Help file doesn’t display for extcap interfaces. Issue 15592.$$$$$$For USB traffic on XHC20 interface destination is always given as Host. Issue 16768.$$$$$$Wireshark Expert Info - cannot deselect the limit to display filter tick box. Issue 18461.$$$$$$Wrong pointer conversion in get_data_source_tvb_by_name() Issue 18517.$$$$$$Wrong number of bits skipped while decoding an empty UTF8String on UPER packet. Issue 18702.$$$$$$Crash when analyzing protobuf packets. Issue 18730.$$$$$$Uninitialized values in various dissectors. Issue 18742.$$$$$$String (GeoIP country/city) ordering doesn’t work in Endpoints. Issue 18749.$$$$$$Wireshark crashes with an assertion failure on stray minus in filter. Issue 18750.$$$$$$IO Graph: Add new graph only works until the 10th graph. Issue 18762.$$$$$$Fuzz job crash output: fuzz-2022-12-30-11007.pcap. Issue 18770.$$$$$$Q.850 - error in label for cause 0x7F. Issue 18780.$$$$$$Uninitialized values in CoAP and RTPS dissectors. Issue 18785.$$$$$$Screenshots in AppStream metainfo.xml file not available. Issue 18801.$$$$$$New and Updated Features$$$Removed Features and Support$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$ASTERIX; BEEP; BGP; BPv6; CoAP; EAP; GNW; GSM A-bis P-GSL; iSCSI; ISUP; LwM2M-TLV; MBIM; NBAP; NFS; OBD-II; OPUS; ProtoBuf; RLC; ROHC; RTPS; Telnet; TIPC; and USB$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.
Wireshark EXE x86 Version 3.6.11
Wireshark 3.6.11 Release Notes$$$What is Wireshark?$$$Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting; analysis; development and education.$$$$$$What’s New$$$This is the last release branch with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2023-02 NFS dissector memory leak. Issue 18628.$$$$$$wnpa-sec-2023-03 Dissection engine crash. Issue 18766.$$$$$$wnpa-sec-2023-04 GNW dissector crash. Issue 18779.$$$$$$wnpa-sec-2023-05 iSCSI dissector crash. Issue 18796.$$$$$$wnpa-sec-2023-06 Multiple dissector excessive loops. Issue 18711. Issue 18720; Issue 18737.$$$$$$wnpa-sec-2023-07 TIPC dissector crash. Issue 18770.$$$$$$The following bugs have been fixed:$$$$$$Qt: After modifying coloring rules; the coloring rule applied to the first packet reflects the coloring rules previously in effect. Issue 12475.$$$$$$Help file doesn’t display for extcap interfaces Issue 15592.$$$$$$Dissector bug; protocol DRBD Issue 16689.$$$$$$For USB traffic on XHC20 interface destination is always given as Host Issue 16768.$$$$$$Wrong pointer conversion in get_data_source_tvb_by_name() Issue 18517.$$$$$$Wrong number of bits skipped while decoding an empty UTF8String on UPER packet Issue 18702.$$$$$$Uninitialized values in various dissectors Issue 18742.$$$$$$Q.850 - error in label for cause 0x7F Issue 18780.$$$$$$Uninitialized values in CoAP and RTPS dissectors Issue 18785.$$$$$$Screenshots in AppStream metainfo.xml file not available Issue 18801.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$BEEP; BGP; BPv6; BSSGP; CoAP; GNW; GSM A-bis P-GSL; GSM BSSMAP; iSCSI; ISUP; Kafka; LwM2M-TLV; NAS-5GS; NFS; OPUS; RLC; ROHC; RTPS; TCP; Telnet; and USB$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.
Wireshark MSI x64 Version 4.0.3.0
Wireshark 4.0.3 Release Notes$$$What is Wireshark?$$$Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting; analysis; development and education.$$$$$$What’s New$$$We do not ship official 32-bit Windows packages for Wireshark 4.0 and later. If you need to use Wireshark on that platform; we recommend using the latest 3.6 release. Issue 17779$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2023-01 EAP dissector crash. Issue 18622.$$$$$$wnpa-sec-2023-02 NFS dissector memory leak. Issue 18628.$$$$$$wnpa-sec-2023-03 Dissection engine crash. Issue 18766.$$$$$$wnpa-sec-2023-04 GNW dissector crash. Issue 18779.$$$$$$wnpa-sec-2023-05 iSCSI dissector crash. Issue 18796.$$$$$$wnpa-sec-2023-06 Multiple dissector excessive loops. Issue 18711. Issue 18720; Issue 18737.$$$$$$wnpa-sec-2023-07 TIPC dissector crash. Issue 18770.$$$$$$The following bugs have been fixed:$$$$$$Qt: After modifying coloring rules; the coloring rule applied to the first packet reflects the coloring rules previously in effect. Issue 12475.$$$$$$Help file doesn’t display for extcap interfaces. Issue 15592.$$$$$$For USB traffic on XHC20 interface destination is always given as Host. Issue 16768.$$$$$$Wireshark Expert Info - cannot deselect the limit to display filter tick box. Issue 18461.$$$$$$Wrong pointer conversion in get_data_source_tvb_by_name() Issue 18517.$$$$$$Wrong number of bits skipped while decoding an empty UTF8String on UPER packet. Issue 18702.$$$$$$Crash when analyzing protobuf packets. Issue 18730.$$$$$$Uninitialized values in various dissectors. Issue 18742.$$$$$$String (GeoIP country/city) ordering doesn’t work in Endpoints. Issue 18749.$$$$$$Wireshark crashes with an assertion failure on stray minus in filter. Issue 18750.$$$$$$IO Graph: Add new graph only works until the 10th graph. Issue 18762.$$$$$$Fuzz job crash output: fuzz-2022-12-30-11007.pcap. Issue 18770.$$$$$$Q.850 - error in label for cause 0x7F. Issue 18780.$$$$$$Uninitialized values in CoAP and RTPS dissectors. Issue 18785.$$$$$$Screenshots in AppStream metainfo.xml file not available. Issue 18801.$$$$$$New and Updated Features$$$Removed Features and Support$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$ASTERIX; BEEP; BGP; BPv6; CoAP; EAP; GNW; GSM A-bis P-GSL; iSCSI; ISUP; LwM2M-TLV; MBIM; NBAP; NFS; OBD-II; OPUS; ProtoBuf; RLC; ROHC; RTPS; Telnet; TIPC; and USB$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.
Wireshark EXE x64 Version 4.0.2
What’s New$$$We do not ship official 32-bit Windows packages for Wireshark 4.0 and later. If you need to use Wireshark on that platform; we recommend using the latest 3.6 release. Issue 17779$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2022-09 Multiple dissector infinite loops.$$$$$$wnpa-sec-2022-10 Kafka dissector memory exhaustion.$$$$$$The following bugs have been fixed:$$$$$$Qt: Endpoints dialog - unexpected byte unit suffixes in packet columns. Issue 18229.$$$$$$GOOSE: field floating_point not working anymore. Issue 18491.$$$$$$EVS Header-Full format padding issues. Issue 18498.$$$$$$Wireshark 4.0.0 VOIP playback has no sound and can’t resume after pausing. Issue 18510.$$$$$$Wireshark crashes when exporting a profile on Mac OSX if there is no extension. Issue 18525.$$$$$$EVS dissector missing value description. Issue 18550.$$$$$$Qt 6 font descriptions not backward compatible with Qt 5. Issue 18553.$$$$$$Wireshark; wrong TCP ACKed unseen segment message. Issue 18558.$$$$$$Invalid Cyrillic symbol in timezone at \Arrival Time\ field in frame. Issue 18562.$$$$$$ProtoBuf parse extension definitions failed. Issue 18599.$$$$$$Fuzz job crash output: fuzz-2022-11-09-11134.pcap. Issue 18613.$$$$$$Fuzz job crash output: fuzz-2022-11-14-11111.pcap. Issue 18632.$$$$$$Wireshark is using old version of ASN (ETSI TS 125 453 V11.2.0) which is imapacting length of param in the messages. Issue 18646.$$$$$$BGP: False IGMP flags value in EVPN routes (type 6;7;8) Issue 18660.$$$$$$wslog assumes stderr and stdout exist. Issue 18684.$$$$$$Editing packet comments; with non-ASCII characters; on Windows saves them in the local code page; not in UTF-8. Issue 18698.$$$$$$Unable to decrypt PSK based DTLS traffic which uses Connection ID. Issue 18705.$$$$$$HTTP2 tests fail when built without nghttp2. Issue 18707.$$$$$$New and Updated Features$$$Removed Features and Support$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$ASN.1 PER; ASTERIX; BGP; BPv6; DTLS; EVS; GOOSE; GSM Osmux; IPv6; Kafka; Locamation IM; MONGO; NXP 802.15.4; OpenFlow v6; PCAP; Protobuf; RTP; S1AP; SKINNY; TCP; and WASSP$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$for more details refer below link$$$https://www.wireshark.org/docs/relnotes/wireshark-4.0.2.html
Wireshark MSI x86 Version 3.6.10.0
Wireshark 3.6.10 Release Notes$$$What is Wireshark?$$$Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting; analysis; development and education.$$$$$$What’s New$$$This is the last release branch with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2022-09 Multiple dissector infinite loops.$$$$$$wnpa-sec-2022-10 Kafka dissector memory exhaustion.$$$$$$The following bugs have been fixed:$$$$$$Packet bytes not displayed completely if scrolling Issue 18438.$$$$$$GOOSE: field floating_point not working anymore Issue 18491.$$$$$$EVS dissector missing value description Issue 18550.$$$$$$ProtoBuf parse extension definitions failed Issue 18599.$$$$$$Fuzz job crash output: fuzz-2022-11-09-11134.pcap Issue 18613.$$$$$$Wireshark is using old version of ASN (ETSI TS 125 453 V11.2.0) which is imapacting length of param in the messages Issue 18646.$$$$$$BGP: False IGMP flags value in EVPN routes (type 6;7;8) Issue 18660.$$$$$$wslog assumes stderr and stdout exist Issue 18684.$$$$$$Editing packet comments; with non-ASCII characters; on Windows saves them in the local code page; not in UTF-8. Issue 18698.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$ASN.1 PER; BGP; BPv6; EVS; GOOSE; GSM Osmux; Kafka; Mongo; NXP 802.15.4; OpenFlow; PCAP; S1AP; and WASSP$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.
Wireshark EXE x86 Version 3.6.10
Wireshark 3.6.10 Release Notes$$$What is Wireshark?$$$Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting; analysis; development and education.$$$$$$What’s New$$$This is the last release branch with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2022-09 Multiple dissector infinite loops.$$$$$$wnpa-sec-2022-10 Kafka dissector memory exhaustion.$$$$$$The following bugs have been fixed:$$$$$$Packet bytes not displayed completely if scrolling Issue 18438.$$$$$$GOOSE: field floating_point not working anymore Issue 18491.$$$$$$EVS dissector missing value description Issue 18550.$$$$$$ProtoBuf parse extension definitions failed Issue 18599.$$$$$$Fuzz job crash output: fuzz-2022-11-09-11134.pcap Issue 18613.$$$$$$Wireshark is using old version of ASN (ETSI TS 125 453 V11.2.0) which is imapacting length of param in the messages Issue 18646.$$$$$$BGP: False IGMP flags value in EVPN routes (type 6;7;8) Issue 18660.$$$$$$wslog assumes stderr and stdout exist Issue 18684.$$$$$$Editing packet comments; with non-ASCII characters; on Windows saves them in the local code page; not in UTF-8. Issue 18698.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$ASN.1 PER; BGP; BPv6; EVS; GOOSE; GSM Osmux; Kafka; Mongo; NXP 802.15.4; OpenFlow; PCAP; S1AP; and WASSP$$$$$$New and Updated Capture File Support$$$There is no new or updated capture file support in this release.$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.
Wireshark MSI x64 Version 4.0.2.0
What’s New$$$We do not ship official 32-bit Windows packages for Wireshark 4.0 and later. If you need to use Wireshark on that platform; we recommend using the latest 3.6 release. Issue 17779$$$$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2022-09 Multiple dissector infinite loops.$$$$$$wnpa-sec-2022-10 Kafka dissector memory exhaustion.$$$$$$The following bugs have been fixed:$$$$$$Qt: Endpoints dialog - unexpected byte unit suffixes in packet columns. Issue 18229.$$$$$$GOOSE: field floating_point not working anymore. Issue 18491.$$$$$$EVS Header-Full format padding issues. Issue 18498.$$$$$$Wireshark 4.0.0 VOIP playback has no sound and can’t resume after pausing. Issue 18510.$$$$$$Wireshark crashes when exporting a profile on Mac OSX if there is no extension. Issue 18525.$$$$$$EVS dissector missing value description. Issue 18550.$$$$$$Qt 6 font descriptions not backward compatible with Qt 5. Issue 18553.$$$$$$Wireshark; wrong TCP ACKed unseen segment message. Issue 18558.$$$$$$Invalid Cyrillic symbol in timezone at \Arrival Time\ field in frame. Issue 18562.$$$$$$ProtoBuf parse extension definitions failed. Issue 18599.$$$$$$Fuzz job crash output: fuzz-2022-11-09-11134.pcap. Issue 18613.$$$$$$Fuzz job crash output: fuzz-2022-11-14-11111.pcap. Issue 18632.$$$$$$Wireshark is using old version of ASN (ETSI TS 125 453 V11.2.0) which is imapacting length of param in the messages. Issue 18646.$$$$$$BGP: False IGMP flags value in EVPN routes (type 6;7;8) Issue 18660.$$$$$$wslog assumes stderr and stdout exist. Issue 18684.$$$$$$Editing packet comments; with non-ASCII characters; on Windows saves them in the local code page; not in UTF-8. Issue 18698.$$$$$$Unable to decrypt PSK based DTLS traffic which uses Connection ID. Issue 18705.$$$$$$HTTP2 tests fail when built without nghttp2. Issue 18707.$$$$$$New and Updated Features$$$Removed Features and Support$$$New Protocol Support$$$There are no new protocols in this release.
Wireshark EXE x86 Version 3.6.9
What’s New$$$This is the last release branch with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779$$$$$$Bug Fixes$$$wnpa-sec-2022-07 OPUS dissector crash. Issue 18378.$$$$$$wnpa-sec-2022-08 USB-HID dissector crash on Windows. Issue 18384.$$$$$$The following bugs have been fixed:$$$$$$Wireshark no longer calculates Statistics ? Service Response Time ? FC properly. Issue 16084.$$$$$$Qt: Crash when opening Statistics ? Service Response Time ? DCE-RPC. Issue 18319.$$$$$$Qt: Crash when closing 3 of the 14 dialogs available from the menu item Statistics ? 29West Issue 18334.$$$$$$TCP: Dissector bug; protocol TCP; in packet 13: …?/wireshark/epan/reassemble.c:1420: failed assertion tvb_bytes_exist(tvb; offset; frag_data_len) Issue 18335.$$$$$$Packet diagram field values are not terminated Issue 18428.$$$$$$Decoding bug H.245 userInput Signal Issue 18468.$$$$$$CFDP dissector doesn’t handle destination filename only Issue 18495.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$ASN.1 PER; BGP; CFDP; FC; GSMTAP; GTP; HTTP; IEEE 802.11; IPv4; ISAKMP; NAS-5GS; OPUS; PFCP; RTPS; TCP; and USB HID$$$$$$New and Updated Capture File Support$$$BLF$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.$$$$$$For more information refer the below link$$$https://www.wireshark.org/docs/relnotes/wireshark-3.6.9.html
Wireshark EXE x64 Version 4.0.1
What’s New$$$We do not ship official 32-bit Windows packages for Wireshark 4.0 and later. If you need to use Wireshark on that platform; we recommend using the latest 3.6 release. Issue 17779$$$$$$The Windows installers now ship with Qt 5.12.2. They previously shipped with Qt 6.2.3.$$$$$$Bug Fixes$$$The following bugs have been fixed:$$$$$$Comparing a boolean field against 1 always succeeds on big-endian machines. Issue 12236.$$$$$$Qt: MaxMind GeoIP columns not added to Endpoints table. Issue 18320.$$$$$$Fuzz job crash output: fuzz-2022-10-04-7131.pcap. Issue 18402.$$$$$$The RTP player might not play audio on Windows. Issue 18413.$$$$$$Wireshark 4.0 breaks display filter expression with > sign. Issue 18418.$$$$$$Capture filters not working when using SSH capture and dumpcap. Issue 18420.$$$$$$Packet diagram field values are not terminated. Issue 18428.$$$$$$Packet bytes not displayed completely if scrolling. Issue 18438.$$$$$$Fuzz job crash output: fuzz-2022-10-13-7166.pcap. Issue 18467.$$$$$$Decoding bug H.245 userInput Signal. Issue 18468.$$$$$$CFDP dissector doesn’t handle \destination filename\ only. Issue 18495.$$$$$$Home page capture button doesn’t pop up capture options dialog. Issue 18506.$$$$$$Missing dot in H.248 protocol name. Issue 18513.$$$$$$Missing dot for protocol H.264 in protocol column. Issue 18524.$$$$$$Fuzz job crash output: fuzz-2022-10-23-7240.pcap. Issue 18534.$$$$$$New and Updated Features$$$Removed Features and Support$$$The experimental display filter syntax for literals using angle brackets <…?> that was introduced in Wireshark 4.0.0 has been removed. For byte arrays a colon prefix can be used instead. See the User’s Guide for details.$$$$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$ASN.1 PER; CFDP; Diameter; DirectPlay; F5 Ethernet Trailer; GTP; H.223; H.248; H.264; H.265; IEEE 802.11; IPv4; MBIM; O-RAN FH CUS; PFCP; RTCP; SCTP; SMB; TCP; and TRANSUM$$$$$$New and Updated Capture File Support$$$BLF$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.$$$$$$For More details refer the below link$$$https://www.wireshark.org/docs/relnotes/wireshark-4.0.1.html
Wireshark EXE x64 Version 4.0.0
What’s New$$$We no longer ship official 32-bit Windows packages starting with this release. If you need to use Wireshark on that platform; we recommend using the latest 3.6 release. Issue 17779$$$$$$The display filter syntax is more powerful with many new extensions. See below for details.$$$$$$The Conversation and Endpoint dialogs have been redesigned. See below for details.$$$$$$The default main window layout has been changed so that the Packet Detail and Packet Bytes are side by side underneath the Packet List pane.$$$$$$Hex dump imports from Wireshark and from text2pcap have been improved. See below for details.$$$$$$Speed when using MaxMind geolocation has been greatly improved.$$$$$$The tools and libraries required to build Wireshark have changed. See “Other Development Changes” below for more details.$$$$$$Many other improvements have been made. See the “New and Updated Features” section below for more details.$$$$$$New and Updated Features$$$The following features are new (or have been significantly updated) since version 4.0.0rc2:$$$$$$Nothing of note.$$$$$$The following features are new (or have been significantly updated) since version 4.0.0rc1:$$$$$$The macOS packages now ship with Qt 6.2.4 and require macOS 10.14. They previously shipped with Qt 5.15.3.$$$$$$The Windows installers now ship with Npcap 1.71. They previously shipped with Npcap 1.70.$$$$$$For more refer : https://www.wireshark.org/docs/relnotes/wireshark-4.0.0.html
Wireshark EXE x86 Version 3.6.8
Note$$$This is the last release branch with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2022-06 F5 Ethernet Trailer dissector infinite loop. Issue 18307.$$$$$$The following bugs have been fixed:$$$$$$TCAP Malformed exception on externally re-assembled packet Issue 10515.$$$$$$Extended 3GPP-GPRS-Negotiated-QoS-profile strings decoded incompletely Issue 10688.$$$$$$HTTP2 dissector decodes first SSL record only Issue 11173.$$$$$$L2TP improvements - cookie length detection; UDP encapsulation and more Issue 16565.$$$$$$USB Truncation of URB_isochronous in frames Issue 18021.$$$$$$ISUP/BICC parameter summary text duplication Issue 18094.$$$$$$Running rpm-setup.sh shows missing packages that Centos does not need Issue 18166.$$$$$$IPX/IPX RIP: Crash on expand subtree Issue 18234.$$$$$$Qt: A file or packet comment that is too large will corrupt the pcapng file Issue 18235.$$$$$$BGP dissector bug Issue 18248.$$$$$$Wrong interpretation of the cbsp.rep_period field in epan/dissectors/packet-gsm_cbsp.c Issue 18254.$$$$$$Assertion due to incorrect mask for btatt.battery_power_state.* Issue 18267.$$$$$$Qt: Expert Info dialog not showing Malformed Frame when Frame length is less than captured length Issue 18312.$$$$$$Wireshark and tshark become non-responsive when reading certain packets Issue 18313.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$BGP; BICC; BT ATT; CBSP; Couchbase; F5 Ethernet Trailer; Frame; GTP; GTP (prime); IPsec; ISUP; L2TP; NAS-5GS; Protobuf; SCCP; TCP; and TLS$$$$$$New and Updated Capture File Support$$$pcap; pcapng$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.$$$$$$Getting Wireshark$$$Wireshark source code and installation packages are available from https://www.wireshark.org/download.html.$$$$$$Vendor-supplied Packages$$$Most Linux and Unix vendors supply their own Wireshark packages. You can usually install or upgrade Wireshark using the package management system specific to that platform. A list of third-party packages can be found on the download page on the Wireshark web site.$$$$$$File Locations$$$Wireshark and TShark look in several different locations for preference files; plugins; SNMP MIBS; and RADIUS dictionaries. These locations vary from platform to platform. You can use Help › About Wireshark › Folders or tshark -G folders to find the default locations on your system.
Wireshark MSI x86 Version 3.6.8.0
Note$$$This is the last release branch with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2022-06 F5 Ethernet Trailer dissector infinite loop. Issue 18307.$$$$$$The following bugs have been fixed:$$$$$$TCAP Malformed exception on externally re-assembled packet Issue 10515.$$$$$$Extended 3GPP-GPRS-Negotiated-QoS-profile strings decoded incompletely Issue 10688.$$$$$$HTTP2 dissector decodes first SSL record only Issue 11173.$$$$$$L2TP improvements - cookie length detection; UDP encapsulation and more Issue 16565.$$$$$$USB Truncation of URB_isochronous in frames Issue 18021.$$$$$$ISUP/BICC parameter summary text duplication Issue 18094.$$$$$$Running rpm-setup.sh shows missing packages that Centos does not need Issue 18166.$$$$$$IPX/IPX RIP: Crash on expand subtree Issue 18234.$$$$$$Qt: A file or packet comment that is too large will corrupt the pcapng file Issue 18235.$$$$$$BGP dissector bug Issue 18248.$$$$$$Wrong interpretation of the cbsp.rep_period field in epan/dissectors/packet-gsm_cbsp.c Issue 18254.$$$$$$Assertion due to incorrect mask for btatt.battery_power_state.* Issue 18267.$$$$$$Qt: Expert Info dialog not showing Malformed Frame when Frame length is less than captured length Issue 18312.$$$$$$Wireshark and tshark become non-responsive when reading certain packets Issue 18313.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$BGP; BICC; BT ATT; CBSP; Couchbase; F5 Ethernet Trailer; Frame; GTP; GTP (prime); IPsec; ISUP; L2TP; NAS-5GS; Protobuf; SCCP; TCP; and TLS$$$$$$New and Updated Capture File Support$$$pcap; pcapng$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.$$$$$$Getting Wireshark$$$Wireshark source code and installation packages are available from https://www.wireshark.org/download.html.$$$$$$Vendor-supplied Packages$$$Most Linux and Unix vendors supply their own Wireshark packages. You can usually install or upgrade Wireshark using the package management system specific to that platform. A list of third-party packages can be found on the download page on the Wireshark web site.$$$$$$File Locations$$$Wireshark and TShark look in several different locations for preference files; plugins; SNMP MIBS; and RADIUS dictionaries. These locations vary from platform to platform. You can use Help › About Wireshark › Folders or tshark -G folders to find the default locations on your system.
Wireshark MSI x64 Version 3.6.8.0
Note$$$This is the last release branch with support for 32-bit Windows. Updates will no longer be available after May 22; 2024 for that platform. Issue 17779$$$Bug Fixes$$$The following vulnerabilities have been fixed:$$$$$$wnpa-sec-2022-06 F5 Ethernet Trailer dissector infinite loop. Issue 18307.$$$$$$The following bugs have been fixed:$$$$$$TCAP Malformed exception on externally re-assembled packet Issue 10515.$$$$$$Extended 3GPP-GPRS-Negotiated-QoS-profile strings decoded incompletely Issue 10688.$$$$$$HTTP2 dissector decodes first SSL record only Issue 11173.$$$$$$L2TP improvements - cookie length detection; UDP encapsulation and more Issue 16565.$$$$$$USB Truncation of URB_isochronous in frames Issue 18021.$$$$$$ISUP/BICC parameter summary text duplication Issue 18094.$$$$$$Running rpm-setup.sh shows missing packages that Centos does not need Issue 18166.$$$$$$IPX/IPX RIP: Crash on expand subtree Issue 18234.$$$$$$Qt: A file or packet comment that is too large will corrupt the pcapng file Issue 18235.$$$$$$BGP dissector bug Issue 18248.$$$$$$Wrong interpretation of the cbsp.rep_period field in epan/dissectors/packet-gsm_cbsp.c Issue 18254.$$$$$$Assertion due to incorrect mask for btatt.battery_power_state.* Issue 18267.$$$$$$Qt: Expert Info dialog not showing Malformed Frame when Frame length is less than captured length Issue 18312.$$$$$$Wireshark and tshark become non-responsive when reading certain packets Issue 18313.$$$$$$New and Updated Features$$$New Protocol Support$$$There are no new protocols in this release.$$$$$$Updated Protocol Support$$$BGP; BICC; BT ATT; CBSP; Couchbase; F5 Ethernet Trailer; Frame; GTP; GTP (prime); IPsec; ISUP; L2TP; NAS-5GS; Protobuf; SCCP; TCP; and TLS$$$$$$New and Updated Capture File Support$$$pcap; pcapng$$$$$$New File Format Decoding Support$$$There is no new or updated file format support in this release.$$$$$$Getting Wireshark$$$Wireshark source code and installation packages are available from https://www.wireshark.org/download.html.$$$$$$Vendor-supplied Packages$$$Most Linux and Unix vendors supply their own Wireshark packages. You can usually install or upgrade Wireshark using the package management system specific to that platform. A list of third-party packages can be found on the download page on the Wireshark web site.$$$$$$File Locations$$$Wireshark and TShark look in several different locations for preference files; plugins; SNMP MIBS; and RADIUS dictionaries. These locations vary from platform to platform. You can use Help › About Wireshark › Folders or tshark -G folders to find the default locations on your system.
Wireshark MSI x64 Version 3.6.7.0
Refer https://www.wireshark.org/docs/relnotes/wireshark-3.6.7.html for more details.