Debian Security Advisory 1417-1 – Tilghman Lesher discovered that the logging engine of Asterisk, a free software PBX and telephony toolkit performs insufficient sanitizing of call-related data, which may lead to SQL injection.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/61431/dsa-1417-1.txt
Source: https://packetstormsecurity.com/files/61431/Debian-Linux-Security-Advisory-1417-1.html

