Echo: libxslt: security update to 1.1.34-4+deb11u3

high Tenable Self-Hosted Container Security Plugin ID 461299

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and
input data, which can lead to type confusion during XML transformations. This vulnerability allows an
attacker to crash the application or corrupt memory. In some cases, it may lead to denial of service or
unexpected behavior. (CVE-2025-7424)

Solution

Update the libxslt library and its related packages to version 1.1.34-4+deb11u3 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-7424

Plugin Details

Severity: High

ID: 461299

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.66

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2025-7424

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 7/10/2025

Reference Information

CVE: CVE-2025-7424