Updated LogWatch packages are available that fix tmp file race conditions which can cause a local user to gain root privileges.
LogWatch is a customizable log analysis system which is used by default in Red Hat Linux 7.2. Versions of LogWatch 2.1.1 and earlier have a vulnerability due to a race condition during the creation of a temporary directory. This vulnerability can allow a local user to gain root privileges. An additional race condition was found in versions of LogWatch 2.5 and earlier. Users should update to the errata packages containing Logwatch 2.6, which are not vulnerable to these issues. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2002-0162 and CAN-2002-0165 to these issues.