Asterisk Project Security Advisory – An attacker may request an Asterisk server to send part of a firmware image. However, as this firmware download protocol does not initiate a handshake, the source address may be spoofed. Therefore, an IAX2 FWDOWNL request for a firmware file may consume as little as 40 bytes, yet produces a 1040 byte response. Coupled with multiple geographically diverse Asterisk servers, an attacker may flood an victim site with unwanted firmware packets.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/68461/AST-2008-011.txt
Source: https://packetstormsecurity.com/files/68461/AST-2008-011.txt.html

