Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2005-1061

12 documents8 sources
Severity
5.0MEDIUM
EPSS
5.7%
top 9.62%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMay 2
Latest updateMay 1

Description

The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch from detecting malicious activity via certain strings in the secure file that are later used as part of a regular expression, which causes the parser to crash, aka "logwatch log processing regular expression DoS."

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

Also affects: Enterprise Linux 2.1

🔴Vulnerability Details

3
GHSA
GHSA-3qhc-99ww-4gq4: The secure script in LogWatch before 22022-05-01
OSV
CVE-2005-1061: The secure script in LogWatch before 22005-05-02
CVEList
CVE-2005-1061: The secure script in LogWatch before 22005-04-21

💥Exploits & PoCs

1
Exploit-DB
Logwatch 2.6 Secure Script - Denial of Service2005-04-20

📋Vendor Advisories

2
Debian
CVE-2005-1061: logwatch - The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch ...2005
Red Hat
security flaw2004-10-28

💬Community

5
Bugzilla
CVE-2005-1061 security flaw2018-08-16
Bugzilla
CVE-2005-3353 PHP exif data DoS2005-11-07
Bugzilla
CVE-2005-3388 PHP phpinfo() XSS attack2005-11-01
Bugzilla
CVE-2005-3390 PHP register globals arbitrary code execution2005-11-01
Bugzilla
CVE-2005-3389 PHP parse_str can enable register_globals2005-11-01