<html>
<head>
<base href="https://bugs.documentfoundation.org/">
</head>
<body><table border="1" cellspacing="0" cellpadding="8">
<tr>
<th>Bug ID</th>
<td><a class="bz_bug_link
bz_status_UNCONFIRMED "
title="UNCONFIRMED - LibreOffice apparently executes embedded website code"
href="https://bugs.documentfoundation.org/show_bug.cgi?id=121711">121711</a>
</td>
</tr>
<tr>
<th>Summary</th>
<td>LibreOffice apparently executes embedded website code
</td>
</tr>
<tr>
<th>Product</th>
<td>LibreOffice
</td>
</tr>
<tr>
<th>Version</th>
<td>6.1.3.2 release
</td>
</tr>
<tr>
<th>Hardware</th>
<td>All
</td>
</tr>
<tr>
<th>OS</th>
<td>Linux (All)
</td>
</tr>
<tr>
<th>Status</th>
<td>UNCONFIRMED
</td>
</tr>
<tr>
<th>Severity</th>
<td>normal
</td>
</tr>
<tr>
<th>Priority</th>
<td>medium
</td>
</tr>
<tr>
<th>Component</th>
<td>Writer
</td>
</tr>
<tr>
<th>Assignee</th>
<td>libreoffice-bugs@lists.freedesktop.org
</td>
</tr>
<tr>
<th>Reporter</th>
<td>yanestra@gmail.com
</td>
</tr></table>
<p>
<div>
<pre>Description:
I have an ODT document created from a web page years ago by using copy & paste.
When I open the ODT document now with LibreOffice 6.1.3.2 as of Debian Buster
(testing) 6.1.3-1, I get two error dialog popups "Error: General Error. General
input/output error." which lack any useful information. In the LibreOficce
document history I can see that LO tried to open a document named
"<a href="http:tweet_button">http:tweet_button</a>.<hexadecimal code>.html".
I need to add that this behaviour is quite new, older versions of LibreOffice
apparently ignored the embedded code (which I can determine from the time to
load and display the document and, there was no error message).
I can only conclude that LibreOffice has tried to execute certain parts of
invisibly embedded JavaScript code or comparable code mechanisms.
Which is categorically undesirable. Copy & Paste should not embed active code.
ODT should not execute embedded website code which is unsuitable in office
documents.
Steps to Reproduce:
1. Load document.
2.
3.
Actual Results:
Waiting time. Two error pop-up dialogs. File history: Attempted tweet button
document load.
Expected Results:
Active elements (code) should be ignored in ODT loading.
Reproducible: Always
User Profile Reset: No
OpenGL enabled: Yes
Additional Info:</pre>
</div>
</p>
<hr>
<span>You are receiving this mail because:</span>
<ul>
<li>You are the assignee for the bug.</li>
</ul>
</body>
</html>