Logwatch contains a flaw related to logwatch.pl failing to properly sanitize log file filenames before use in 'system()' calls. This may allow a remote attacker to inject and execute shell commands.
Currently, there are no known workarounds or upgrades to correct this issue. However, the Logwatch team has released a patch to address this vulnerability.