2 <!DOCTYPE article PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN"
3 "http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd" [
9 -Use this section to encode all document information
15 <!ENTITY WiresharkCurrentVersion "0.99.4">
20 <title>Wireshark &WiresharkCurrentVersion; Release Notes</title>
22 <section id="WhatIs"><title>What is Wireshark?</title>
24 Wireshark is the world's most popular network protocol analyzer. It
25 is used for troubleshooting, analysis, development, and education.
29 <section id="WhatsNew"><title>What's New</title>
30 <section><title>Bug Fixes</title>
33 The following vulnerabilities have been fixed. See the
34 <ulink url="http://www.wireshark.org/security/wnpa-sec-2006-02.html">security advisory</ulink> for details and a workaround.
39 The HTTP dissector could crash.
40 <!-- Fixed in r19022, r19153 -->
41 <!-- Bug IDs: 1050, 1079 -->
42 Versions affected: 0.99.3.
46 The LDAP dissector (and possibly others) could crash.
47 <!-- Fixed in r19154 -->
48 <!-- Bug IDs: 1079 -->
49 Versions affected: 0.99.3.
53 The XOT dissector could attempt to allocate a large amount of memory and crash.
54 <!-- Fixed in r19365 -->
55 <!-- Bug IDs: 1133 -->
56 Versions affected: 0.9.8 to 0.99.3.
60 If AirPcap support was enabled, parsing a WEP key could sometimes cause a crash.
61 <!-- Fixed in r19401 -->
62 <!-- Bug IDs: None -->
63 Versions affected: 0.99.3.
72 The following bugs have been fixed:
77 The file set dialog could grow excessively large.
78 (<ulink url="http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=331">Bug
83 Trying to save flow data may crash Wireshark.
84 (<ulink url="http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=396">Bug
89 It may not be possible to re-order coloring rules under Windows.
90 (<ulink url="http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=699">Bug
95 Printing each packet to a new page didn't work under Windows.
96 (<ulink url="http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=707">Bug
101 The personal hosts configuration file wasn't being parsed correctly.
102 (<ulink url="http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=795">Bug
107 "Save as" to an existing file wasn't allowed.
108 (<ulink url="http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=927">Bug
113 The SNMP dissector was not handling 64-bit counters properly.
114 (<ulink url="http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1047">Bug
119 Wireshark and TShark would fail to start under Windows while trying to acquire a crypto context.
120 (<ulink url="http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1096">Bug
125 Invalid characters could show up in PDML output.
126 (<ulink url="http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1110">Bug
135 <section><title>New and Updated Features</title>
137 The following features are new (or have been significantly updated)
138 since the last release:
142 <ulink url="http://www.cacetech.com/products/airpcap.htm">AirPcap</ulink>,
143 support (which provides raw mode capture under Windows) has been
148 VoIP call playback has been enhanced. If Wireshark is linked with
149 the PortAudio library, you can play back G.711 conversations. This
150 feature is present in the standard Windows installer.
154 The capture interface dialog display has been enhanced.
158 The "Save" button has been removed from the "Ok" / "Apply" / "Cancel"
159 button group in the following dialogs:
161 <listitem><para>Edit/Preferences</para></listitem>
162 <listitem><para>View/Coloring Rules</para></listitem>
163 <listitem><para>Capture/Capture Filters</para></listitem>
164 <listitem><para>Analyze/Display Filters</para></listitem>
165 <listitem><para>"Analyze/Enabled Protocols</para></listitem>
167 If you're fond of the "Save" button it can be resurrected in the
168 User Interface preferences.
172 Reading from stdin ("-i -") now works under Windows.
176 Expert analysis has been improved.
180 Wireshark now supports USB as a media type.
187 <section><title>New Protocol Support</title>
191 Ethernet Powerlink (v1 and v2),
192 H.248 Q.1950 Annex A,
207 <section><title>Updated Protocol Support</title> <para>
225 Common Windows networking,
227 DCERPC (DCERPC, ATSVC, DFS, EFS, EPM, EVENTLOG, INITSHUTDOWN, MAPI, NT, PIPE, SAMR, SPOOLSS, SRVSVC, SVCCTL, WINREG),
228 DCOM (DCOM, CBA-ACCO, SYSACT),
307 <section><title>New and Updated Capture File Support</title>
310 Catapult DCT2000, EyeSDN, iSeries
317 <section id="GettingWireshark"><title>Getting Wireshark</title>
319 Wireshark source code and installation packages are available from
320 the <ulink url="http://www.wireshark.org/download.html">download
321 page</ulink> on the main web site.
324 <section><title>Vendor-supplied Packages</title>
326 Most Linux and Unix vendors supply their own Wireshark packages.
327 You can usually install or upgrade Wireshark using the package management
328 system specific to that platform. A list of third-party packages
330 <ulink url="http://www.wireshark.org/download.html#otherplat">download page</ulink> on the Wireshark web site.
336 <!-- XXX needs to be written
337 <section id="RemovingWireshark"><title>Removing Wireshark</title>
343 <section id="FileLocations"><title>File Locations</title>
345 Wireshark and TShark look in several different locations for
346 preference files, plugins, SNMP MIBS, and RADIUS dictionaries.
347 These locations vary from platform to platform. You can use
348 About->Folders to find the default locations on your system.
352 <section id="KnownProblems"><title>Known Problems</title>
355 On Windows systems the packet list scroll bar can sometimes disappear
356 or become unusable. Until the problem is fixed you can work around it
357 by resizing the packet list or the main window.
358 (<ulink url="http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=220">Bug
363 The <guibutton>Filter</guibutton> button is nonfunctional in the
364 file dialogs under Windows.
365 (<ulink url="http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=942">Bug
371 <section id="GettingHelp"><title>Getting Help</title>
373 Community support is available on the wireshark-users mailing list.
374 Subscription information and archives for all of Wireshark's mailing
375 lists can be found on <ulink url="http://www.wireshark.org/lists/">the
379 Commercial support, training, and development services are available
380 from <ulink url="http://www.cacetech.com/">CACE Technologies</ulink>.
384 <section id="FAQ"><title>Frequently Asked Questions</title>
386 A complete FAQ is available on the
387 <ulink url="http://www.wireshark.org/faq.html">Wireshark web site</ulink>.