Hi Olly,

On Tue, Aug 25, 2026 at 10:18:40AM +1200, Olly Betts wrote:
> Control: clone -1 -2
> Control: retitle -2 antiword: heap out-of-bounds read during OLE property 
> decoding
> Control: severity -2 normal
> Control: tags -2 -security
> Control: tags -1 +unreproducible
> 
> Putting the summary first for the benefit of the security team:

Thanks for that.

> I think you probably tested antiword without any of the existing Debian
> patches applied, and I'm pretty sure you're re-reporting CVE-2014-8123
> which we patched in Debian in 2009.  The reproducer actually shows an
> OOB read (not write) which doesn't look like one that's been reported
> before.  So unless I'm missing something, this isn't something we'd
> handle as a security bug in Debian; if a new CVE has been requested
> for this then the details should be updated there (or mark it as a
> duplicate of CVE-2014-8123 and request a fresh one).

Thanks, so I would suggest to mark 1144644 as fixed with same version
as for the old bug #771768 (for CVE-2014-8123).

Regards,
Salvatore

Reply via email to