Synopsis
The remote FreeBSD host is missing one or more security-related updates.
Description
The version of FreeBSD installed on the remote host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the b0a3466f-5efc-11f0-ae84-99047d0a6bcc advisory.
Alan Coopersmith reports:
On 6/16/25 15:12, Alan Coopersmith wrote:
BTW, users of libxml2 may also be using its sibling project, libxslt, which currently has no active maintainer, but has three unfixed security issues reported against it according to
https://gitlab.gnome.org/Teams/Releng/security/-/wikis/2025#libxml2-and-libxslt
2 of the 3 have now been disclosed:
(CVE-2025-7424) libxslt: Type confusion in xmlNode.psvi between stylesheet and source nodes https://gitlab.gnome.org/GNOME/libxslt/-/issues/139 https://project-zero.issues.chromium.org/issues/409761909 (CVE-2025-7425) libxslt: heap-use-after-free in xmlFreeID caused by `atype` corruption https://gitlab.gnome.org/GNOME/libxslt/-/issues/140https://project- zero.issues.chromium.org/issues/410569369 Engineers from Apple & Google have proposed patches in the GNOME gitlab issues, but neither has had a fix applied to the git repo since there is currently no maintainer for libxslt.
Note that a fourth vulnerability was reported on June 18, 2025, which remains undisclosed to date (GNOME libxslt issue 148, link below), see
https://gitlab.gnome.org/Teams/Releng/security/-/wikis/2025#libxml2-and-libxslt
Tenable has extracted the preceding description block directly from the FreeBSD security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Update the affected packages.
Plugin Details
File Name: freebsd_pkg_b0a3466f5efc11f0ae8499047d0a6bcc.nasl
Supported Sensors: Nessus
Risk Information
Vector: CVSS2#AV:L/AC:H/Au:N/C:N/I:C/A:C
Vector: CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
CPE: cpe:/o:freebsd:freebsd, p-cpe:/a:freebsd:freebsd:linux-c7-libxslt, p-cpe:/a:freebsd:freebsd:libxslt, p-cpe:/a:freebsd:freebsd:linux-rl9-libxslt
Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info
Exploit Ease: No known exploits are available
Patch Publication Date: 7/12/2025
Vulnerability Publication Date: 7/10/2025