When using tcpdump to capture packets to a file, or read packets from a file, the file format used is inconsistent with the version of TCPDUMP on RedHat 6.0 and 5.2 (and probably earlier). It would appear that some alignment issues have occurred, perhaps due to changing compilers (egcs vs. gcc). The net result is that tcpdump-3.4-5 (on a RH5.2 system) for example, cannot read files created on a 6.1 system running tcpdump-3.4-16, or vice versa. Third-party tools, such as EtherPeek (http://www.aggroup.com) are able to read and decode tcpdump files from RedHat 6.0 and previous, but cannot read them from RedHat 6.1. This backs up my contention that the file format in 6.1 is messed up.
*** This bug has been marked as a duplicate of 6773 ***