Logwatch is a log-analysis and alerting utility typically deployed on Unix and Linux systems to parse and summarize system logs, with a narrow but specialized footprint. Its observed vulnerability signal centers on input-validation handling within its log-parsing mechanisms, reflecting the challenges of secure pattern-matching and data interpretation in a tool that processes untrusted or semi-trusted log streams. Current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Logwatch over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-1018HIGH logwatch.pl in Logwatch 7.3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in a log file name, as demonstrated via a crafted username to a Samba s | Feb 25, 2011 | 10.0 | 51 | NO | YES |
CVE-2002-0162MEDIUM LogWatch before 2.5 allows local users to execute arbitrary code via a symlink attack on the logwatch temporary directory. | Mar 27, 2002 | 6.2 | 30 | NO | YES |
CVE-2005-1061MEDIUM The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch from detecting malicious activity via certain strings in the secure file that are later used as part | May 2, 2005 | 5.0 | 23 | NO | YES |
CVE-2002-0165HIGH LogWatch 2.5 allows local users to gain root privileges via a symlink attack, a different vulnerability than CVE-2002-0162. | Apr 3, 2002 | 7.2 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Logwatch.
Media articles that mention a CVE ID that affects a product developed by Logwatch — matched by CVE ID, not by vendor name.