CVE-2017-20148: Debian Logcheck

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

In the ebuild package through logcheck-1.3.23.ebuild for Logcheck on Gentoo, it is possible to achieve root privilege escalation from the logcheck user because of insecure recursive chown calls.

Affected products

  • Debian Logcheck: up to and including 1.3.23

Published 2022-09-20. Last modified 2026-06-17.