Bug 71281

Summary: [SECURITY] Password removed from ODS file when saving to XLS, XLT...
Product: LibreOffice Reporter: Mikeyy - L10n HR <mihovil>
Component: CalcAssignee: Not Assigned <libreoffice-bugs>
Status: NEW ---    
Severity: major CC: jluth, marina.latini, peergynnt, quikee, yuki.bot
Priority: medium    
Version: 4.1.3.2 release   
Hardware: All   
OS: All   
See Also: https://bugs.freedesktop.org/show_bug.cgi?id=71322
Whiteboard:
Crash report or crash signature: Regression By:
Bug Depends on:    
Bug Blocks: 108897, 108914, 109072    
Attachments: Test password file
password forget

Description Mikeyy - L10n HR 2013-11-05 20:53:08 UTC
Created attachment 88730 [details]
Test password file

This is a security breach bug.

Take any password protected ODS file. For example I made simple ODS file, locked down sheet and document, you cannot even select cells.

1. Open attached file.
2. Save As -> XLS file
3. You will be prompted that passwords aren't hash compatible and if you want to select new password.
4. Select to rewrite password and then select to remove password.
5. After you finish, go to TOOLS - PROTECT DOCUMENT and remove protection from sheet and document.

In 4th step, you can also choose new password instead of removing old, you just need to uncheck "Same password as old password" checkbox.

This affects XLS, XLT, but not XLSX.
Not sure if it affects other formats.
Comment 1 Tomaz Vajngerl 2013-11-06 14:33:44 UTC
This is weird - why is retyping even needed. I saved ODS to XLSX and then reopened the XLSX file and saved as XLS. In this case there was no prompt to retype the password and the XLS was still protected. If it goes from ODS->XLSX->XLS then it must also go from ODS->XLS without the prompt to retype the password.

Anyway - all we need to do is to add a check for the old password in the "Re-type password" Dialog.
Comment 2 Mikeyy - L10n HR 2013-11-06 19:44:19 UTC
Removing password or changing it should have mandatory "Type old password first" prompt.
It looks like you can pretty much crack open any ODS file like this.
Comment 3 Tomaz Vajngerl 2013-11-06 20:51:13 UTC
> It looks like you can pretty much crack open any ODS file like this.

Yes.. now you can. However sheet protection does not encrypt the document anyway so you can easily unzip and remove the protection from the xml file if you want to get rid of the protection.

I will take a look at this bug when time permits. If someone wants to take this bug please say.
Comment 4 QA Administrators 2016-02-21 08:36:40 UTC Comment hidden (obsolete, spam)
Comment 5 durgarao_8in 2019-03-24 10:53:48 UTC
Created attachment 150249 [details]
password forget
Comment 6 m_a_riosv 2019-05-07 20:30:09 UTC
*** Bug 125114 has been marked as a duplicate of this bug. ***
Comment 7 QA Administrators 2021-05-07 03:59:24 UTC Comment hidden (obsolete)
Comment 8 QA Administrators 2023-05-08 03:18:08 UTC Comment hidden (obsolete)
Comment 9 Matt K 2023-12-16 21:58:23 UTC
I can repro this, but the question is: If you really want to encrypt the document such that no one can open it without a password, why don't you try "File"->"Save as..." and check the checkbox for "Save with password", which will ask you to type a password on save, and afterward the document will be encrypted.