Asterisk Project Security Advisory – The Asterisk IAX2 channel driver, chan_iax2, has a remotely exploitable stack buffer overflow vulnerability. It occurs when chan_iax2 is passed a voice or video frame with a data payload larger than 4 kB. This is exploitable by sending a very large RTP frame to an active RTP port number used by Asterisk when the other end of the call is an IAX2 channel. Exploiting this issue can cause a crash or allow arbitrary code execution on a remote machine.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/57816/ASA-2007-014.txt
Source: https://packetstormsecurity.com/files/57816/ASA-2007-014.txt.html