Bug 119811 - LibreOffice 6.0.6 spies on my Firefox keychain when opening MS documents
Summary: LibreOffice 6.0.6 spies on my Firefox keychain when opening MS documents
Status: RESOLVED DUPLICATE of bug 118593
Alias: None
Product: LibreOffice
Classification: Unclassified
Component: LibreOffice (show other bugs)
Version:
(earliest affected)
6.0.6.2 release
Hardware: All Linux (All)
: medium normal
Assignee: Not Assigned
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-09-11 16:47 UTC by libreoffice
Modified: 2018-09-12 10:28 UTC (History)
1 user (show)

See Also:
Crash report or crash signature:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description libreoffice 2018-09-11 16:47:58 UTC
Description:
When opening a docx,xlsx,pptx file, LibreOffice tries to access my Firefox's certificate store and keychain (as reported by default AppArmor rules provided by Canonical on Ubuntu 18.04)
Said files has no digital signature to check, if it were the case, it would be required to use system's certificate store and/or seahorse's certificate store.

Affected versions are 6.0.3 provided by Canonical and 6.0.6 provided by document foundation launchpad PPA.

There are no visible reasons for LibreOffice to try to read anything from Firefox.

Here are the logs produced by AppArmor when opening such files :

home/Magissia/.mozilla/firefox/mwad0hks.default/cert8.db" pid=19509 comm="soffice.bin" requested_mask="w" denied_mask="w" fsuid=1000 ouid=1000
Sep 11 18:25:31 Marshmallow kernel: [18154.693846] audit: type=1400 audit(1536683131.498:70): apparmor="ALLOWED" operation="open" profile="libreoffice-soffice" name="/home/Magissia/.mozilla/firefox/mwad0hks.default/key3.db" pid=19509 comm="soffice.bin" requested_mask="wr" denied_mask="wr" fsuid=1000 ouid=1000
Sep 11 18:25:40 Marshmallow kernel: [18163.215743] audit: type=1400 audit(1536683140.018:71): apparmor="ALLOWED" operation="open" profile="libreoffice-soffice" name="/proc/version" pid=19509 comm="soffice.bin" requested_mask="r" denied_mask="r" fsuid=1000 ouid=0

Steps to Reproduce:
1. Open any docx file created with Microsoft Word 2013 or superior
2. Enjoy invasion of privacy

Actual Results:
LibreOffice tries to read private files that has nothing to do with the document or LibreOffice

Expected Results:
Not reading Firefox's files when opening documents


Reproducible: Always


User Profile Reset: Yes


OpenGL enabled: Yes

Additional Info:
Version: 6.0.6.2
Build ID: 1:6.0.6-0ubuntu0.18.04.1
Threads CPU : 2; OS : Linux 4.15; UI Render : par défaut; VCL: gtk3; 
Locale : fr-FR (fr_FR.UTF-8); Calc: group
Comment 1 Thorsten Behrens (CIB) 2018-09-12 10:28:32 UTC

*** This bug has been marked as a duplicate of bug 118593 ***