CVE-2005-1061

LogWatch - Denial of Service via Secure Script Regular Expression Crash

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-1061. PoCs published by anonymous.

AI-analyzed exploit summary This exploit demonstrates a denial of service (DoS) vulnerability in Logwatch by injecting a malicious string into a log file, causing the utility to fail in detecting subsequent activity. The provided command uses 'logger' to inject the payload into the authpriv.notice log facility.

Description

The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch from detecting malicious activity via certain strings in the secure file that are later used as part of a regular expression, which causes the parser to crash, aka "logwatch log processing regular expression DoS."

Exploits (1)

exploitdb WORKING POC VERIFIED
by anonymous · textdoslinux
https://www.exploit-db.com/exploits/25465

This exploit demonstrates a denial of service (DoS) vulnerability in Logwatch by injecting a malicious string into a log file, causing the utility to fail in detecting subsequent activity. The provided command uses 'logger' to inject the payload into the authpriv.notice log facility.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Logwatch (versions affected by CVE-2005-1061)
No auth needed
Prerequisites: Local access to the system · Ability to write to log files via logger or similar tools
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-364.html

Scores

EPSS 0.0307
EPSS Percentile 86.3%

Details

Status published
Products (3)
logwatch/logwatch 2.6.2
redhat/enterprise_linux 2.1 (3 CPE variants)
redhat/linux_advanced_workstation 2.1
Published May 02, 2005
Tracked Since Feb 18, 2026