New version of #Asterisk fixes a remote crash (and maybe RCE!) in STIR/SHAKEN header parsing: CVE-2025-49832
https://t.co/F0zD2lRAuv
#CVE#appsec#CyberSecurity#VOIP
@JarnoPilovali There's a bit of strange logic. If a request comes in over IPv6, it loads JavaScript to display the IPv4 address, which requires another DNS lookup and another GET request. No other clean way to do it for both protocols, sadly.