During the last four years years, the United Kingdoms Centre for the Protection of National Infrastructure (CPNI) embarked itself into a project to perform a thorough security assessment of the TCP and IP protocols. The project did not limit itself to an analysis of the relevant IETF (Internet Engineering Task Force) specifications, but also included an analysis of common implementation strategies found in popular TCP and IP implementations. As strange as it may sound, this was the first thorough security assessment of the TCP and IP protocols and their common implementation strategies, and the first attempt to take much of the work and wisdom of the security community to the IETF (Internet Engineering Task Force) and the vendor community. During this period of time, a number of vulnerabilities in the TCP protocol were independently reported to some vendors and CSIRTs. During the cooperation process with the affected parties, had a key role in providing advice to vendors on these vulnerabilities and the possible mitigation strategies. Recently, these security issues were finally disclosed by some CSIRTs and some major vendors. However, the security bulletins did not provide much detail about the nature of the vulnerabilities or the possible mitigation strategies. As a result, the information that is currently available about these issues has mostly been "guess work" by some security researchers, and due to the lack of "official" details about these issues it has been difficult to separate "fudge" from fact. Fernando Gont will provide details about the nature of the aforementioned vulnerabilities, and will provide some insights about the possible mitigation strategies.