Hi Olly, On Tue, Aug 25, 2026 at 10:18:40AM +1200, Olly Betts wrote: > Control: clone -1 -2 > Control: retitle -2 antiword: heap out-of-bounds read during OLE property > decoding > Control: severity -2 normal > Control: tags -2 -security > Control: tags -1 +unreproducible > > Putting the summary first for the benefit of the security team:
Thanks for that. > I think you probably tested antiword without any of the existing Debian > patches applied, and I'm pretty sure you're re-reporting CVE-2014-8123 > which we patched in Debian in 2009. The reproducer actually shows an > OOB read (not write) which doesn't look like one that's been reported > before. So unless I'm missing something, this isn't something we'd > handle as a security bug in Debian; if a new CVE has been requested > for this then the details should be updated there (or mark it as a > duplicate of CVE-2014-8123 and request a fresh one). Thanks, so I would suggest to mark 1144644 as fixed with same version as for the old bug #771768 (for CVE-2014-8123). Regards, Salvatore

