AST-2017-005 - A change was made to the strict RTP
	  support in the RTP stack to better tolerate late media
	  when a reinvite occurs. When combined with the symmetric
	  RTP support this introduced an avenue where media could
	  be hijacked. Instead of only learning a new address when
	  expected the new code allowed a new source address to be
	  learned at all times.
	  AST-2017-006 - The app_minivm module has an "externnotify"
	  program configuration option that is executed by the
	  MinivmNotify dialplan application. The application uses
	  the caller-id name and number as part of a built string
	  passed to the OS shell for interpretation and execution.
	  Since the caller-id name and number can come from an
	  untrusted source, a crafted caller-id name or number
	  allows an arbitrary shell command injection.