Bug 71281 - [SECURITY] Password removed from ODS file when saving to XLS, XLT...
Summary: [SECURITY] Password removed from ODS file when saving to XLS, XLT...
Status: NEW
Alias: None
Product: LibreOffice
Classification: Unclassified
Component: Calc (show other bugs)
(earliest affected) release
Hardware: Other Windows (All)
: medium major
Assignee: Not Assigned
: 125114 (view as bug list)
Depends on:
Blocks: XLSX Password-Protected XLS
  Show dependency treegraph
Reported: 2013-11-05 20:53 UTC by Mikeyy - L10n HR
Modified: 2021-05-07 03:59 UTC (History)
4 users (show)

See Also:
Crash report or crash signature:
Regression By:

Test password file (8.39 KB, application/vnd.oasis.opendocument.spreadsheet)
2013-11-05 20:53 UTC, Mikeyy - L10n HR
password forget (12.13 KB, application/vnd.oasis.opendocument.spreadsheet)
2019-03-24 10:53 UTC, durgarao_8in

Note You need to log in before you can comment on or make changes to this bug.
Description Mikeyy - L10n HR 2013-11-05 20:53:08 UTC
Created attachment 88730 [details]
Test password file

This is a security breach bug.

Take any password protected ODS file. For example I made simple ODS file, locked down sheet and document, you cannot even select cells.

1. Open attached file.
2. Save As -> XLS file
3. You will be prompted that passwords aren't hash compatible and if you want to select new password.
4. Select to rewrite password and then select to remove password.
5. After you finish, go to TOOLS - PROTECT DOCUMENT and remove protection from sheet and document.

In 4th step, you can also choose new password instead of removing old, you just need to uncheck "Same password as old password" checkbox.

This affects XLS, XLT, but not XLSX.
Not sure if it affects other formats.
Comment 1 Tomaz Vajngerl 2013-11-06 14:33:44 UTC
This is weird - why is retyping even needed. I saved ODS to XLSX and then reopened the XLSX file and saved as XLS. In this case there was no prompt to retype the password and the XLS was still protected. If it goes from ODS->XLSX->XLS then it must also go from ODS->XLS without the prompt to retype the password.

Anyway - all we need to do is to add a check for the old password in the "Re-type password" Dialog.
Comment 2 Mikeyy - L10n HR 2013-11-06 19:44:19 UTC
Removing password or changing it should have mandatory "Type old password first" prompt.
It looks like you can pretty much crack open any ODS file like this.
Comment 3 Tomaz Vajngerl 2013-11-06 20:51:13 UTC
> It looks like you can pretty much crack open any ODS file like this.

Yes.. now you can. However sheet protection does not encrypt the document anyway so you can easily unzip and remove the protection from the xml file if you want to get rid of the protection.

I will take a look at this bug when time permits. If someone wants to take this bug please say.
Comment 4 QA Administrators 2016-02-21 08:36:40 UTC Comment hidden (obsolete, spam)
Comment 5 durgarao_8in 2019-03-24 10:53:48 UTC
Created attachment 150249 [details]
password forget
Comment 6 m.a.riosv 2019-05-07 20:30:09 UTC
*** Bug 125114 has been marked as a duplicate of this bug. ***
Comment 7 QA Administrators 2021-05-07 03:59:24 UTC
Dear Mikeyy - L10n HR,

To make sure we're focusing on the bugs that affect our users today, LibreOffice QA is asking bug reporters and confirmers to retest open, confirmed bugs which have not been touched for over a year.

There have been thousands of bug fixes and commits since anyone checked on this bug report. During that time, it's possible that the bug has been fixed, or the details of the problem have changed. We'd really appreciate your help in getting confirmation that the bug is still present.

If you have time, please do the following:

Test to see if the bug is still present with the latest version of LibreOffice from https://www.libreoffice.org/download/

If the bug is present, please leave a comment that includes the information from Help - About LibreOffice.
If the bug is NOT present, please set the bug's Status field to RESOLVED-WORKSFORME and leave a comment that includes the information from Help - About LibreOffice.

Please DO NOT

Update the version field
Reply via email (please reply directly on the bug tracker)
Set the bug's Status field to RESOLVED - FIXED (this status has a particular meaning that is not 
appropriate in this case)

If you want to do more to help you can test to see if your issue is a REGRESSION. To do so:
1. Download and install oldest version of LibreOffice (usually 3.3 unless your bug pertains to a feature added after 3.3) from https://downloadarchive.documentfoundation.org/libreoffice/old/

2. Test your bug
3. Leave a comment with your results.
4a. If the bug was present with 3.3 - set version to 'inherited from OOo';
4b. If the bug was not present in 3.3 - add 'regression' to keyword

Feel free to come ask questions or to say hello in our QA chat: https://kiwiirc.com/nextclient/irc.freenode.net/#libreoffice-qa

Thank you for helping us make LibreOffice even better for everyone!

Warm Regards,
QA Team