Bug#1008092: antiword: Possible related RedHat-reported buffer overflow

2023-10-09 Thread Olly Betts
On Tue, Oct 10, 2023 at 12:12:49AM +0100, Tj wrote:
> A package search on the RedHat bugzilla shows other reports including
> tracking bugs for the referenced (security) bug #2064638.
> 
> https://bugzilla.redhat.com/buglist.cgi?component=antiword=Fedora

Doesn't seem promising - there's no useful public info there, but
https://bugzilla.redhat.com/show_bug.cgi?id=2064735 says:

| This CVE Bugzilla entry is for community support informational
| purposes only as it does not affect a package in a commercially
| supported Red Hat product. Refer to the dependent bugs for status of
| those individual community products.

Reads to me like "this doesn't affect RHEL so we aren't interested".
The public bugs at least seem to have just been closed without a fix
being applied.

> It might be worth contacting Adrian Reber for info on this.

If you think it'll help please do.

Cheers,
Olly



Bug#1008092: antiword: Possible related RedHat-reported buffer overflow

2023-10-09 Thread Tj
Package: antiword
Followup-For: Bug #1008092

A package search on the RedHat bugzilla shows other reports including
tracking bugs for the referenced (security) bug #2064638.

https://bugzilla.redhat.com/buglist.cgi?component=antiword=Fedora

It might be worth contacting Adrian Reber for info on this.