The Mu Security Research team has found two security issues in the SDP parser in Asterisk 1.4.18. One is an invalid write to an attacker-controllable, almost arbitrary memory location and the other is a stack buffer overflow with limited attacker-controllable values.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/64724/MU-200803-01.txt
Source: https://packetstormsecurity.com/files/64724/MU-Security-Advisory-2008-03.01.html

