Bug#984703: libreoffice-calc: LibreOffice Calc executes code from current dir (encodings.py) when opening a .csv

2021-03-07 Thread Milko Krachounov
Package: libreoffice-calc Version: 1:6.1.5-3+deb10u6 Severity: grave Tags: security Justification: user security hole Dear Maintainer, When opening any CSV file with LibreOffice Calc, Calc opens and executes encodings.py from the current working directory. That presumably happens because Some f

Bug#984703: libreoffice-calc: LibreOffice Calc executes code from current dir (encodings.py) when opening a .csv

2021-03-07 Thread Rene Engelhard
Hi again, Am 07.03.21 um 13:34 schrieb Milko Krachounov: > When opening any CSV file with LibreOffice Calc, Calc opens and executes > encodings.py from the current working directory. That presumably happens > because There also is no mention of any "encodings.py" in anything in LibreOffice itsel

Bug#984703: libreoffice-calc: LibreOffice Calc executes code from current dir (encodings.py) when opening a .csv

2021-03-07 Thread Rene Engelhard
tag 984703 + moreinfo tag 984703 + unreproducible thanks Hi, Am 07.03.21 um 13:34 schrieb Milko Krachounov: > When opening any CSV file with LibreOffice Calc, Calc opens and executes > encodings.py from the current working directory. Demonstrably wrong, see below. > That presumably happens

Bug#984703: libreoffice-calc: LibreOffice Calc executes code from current dir (encodings.py) when opening a .csv

2021-03-07 Thread Milko Krachounov
Hello, After some additional testing, checking my environment and inspecting pyuno/ source/loader/pyuno_loader.cxx, I want to amend the report, particularly about 7.0.4 which is not affected (kind of). First, I wonder if someone reproduces this on 1:6.1.5-3+deb10u6 (if nobody does, I may whip u

Bug#984703: libreoffice-calc: LibreOffice Calc executes code from current dir (encodings.py) when opening a .csv

2021-03-07 Thread Rene Engelhard
forwarded 984703 https://bugs.documentfoundation.org/show_bug.cgi?id=121384 thanks Hi, Am 07.03.21 um 22:45 schrieb Milko Krachounov: > After some additional testing, checking my environment and inspecting pyuno/ > source/loader/pyuno_loader.cxx, I want to amend the report, particularly > abou

Bug#984703: libreoffice-calc: LibreOffice Calc executes code from current dir (encodings.py) when opening a .csv

2021-03-07 Thread Rene Engelhard
Hi again, Am 07.03.21 um 23:08 schrieb Rene Engelhard: > Am 07.03.21 um 22:45 schrieb Milko Krachounov: >> After some additional testing, checking my environment and inspecting pyuno/ >> source/loader/pyuno_loader.cxx, I want to amend the report, particularly >> about >> 7.0.4 which is not affec