Multiple BSD Vendor IP Fragment Queue Resource Exhaustion Vulnerability

Operating systems derived from BSD contain a vulnerability in the inherited TCP/IP implementation that may lead to possible denial of service conditions.

The problem is that there is no limit to how many IP fragment reassembly queues can be created. A remote attacker may be able to exhaust resources by causing the creation of a large number of reassembly queues.

NetBSD and FreeBSD are vulnerable. OpenBSD and BSDI may also be vulnerable to this attack.


