Bug#749770: Impress listens to the world by default (0.0.0.0:1599)
Package: libreoffice-impress
Version: 1:4.2.4-3
Severity: normal
Tags: upstream
Hello,
the Impress Remote (see e.g.
https://f-droid.org/repository/browse/?fdid=org.libreoffice.impressremote) is
enabled by default, making LibreOffice listen to the world. Additionaly, this
feature is difficult to turn off (Impress must be started to get into Options,
meaning you can't disable socket binding without actually binding)
How to reproduce:
1. Start Impress
2. Observe 'netstat -tulpn | grep office' or telnet localhost 1599
tcp 0 0 0.0.0.0:1599 0.0.0.0:* LISTEN
6513/soffice.bin
udp 0 0 0.0.0.0:1598 0.0.0.0:*
6513/soffice.bin
How to turn off:
1. Start Impress. This unfortunately enables the listening immediately.
2. Tools -> Options -> Impress -> General -> [ ] Enable remote control
I think (at least desktop) applications shouldn't accept connections from the
internet by default.
-- System Information:
Debian Release: jessie/sid
APT prefers unstable
APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386
Kernel: Linux 3.13-1-amd64 (SMP w/4 CPU cores)
Locale: LANG=cs_CZ.utf8, LC_CTYPE=cs_CZ.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash
Versions of packages libreoffice-impress depends on:
ii libc6 2.18-7
ii libetonyek-0.0-0 0.0.4-2
ii libgcc1 1:4.9.0-5
ii libodfgen-0.0-0 0.0.4-2
ii libreoffice-core 1:4.2.4-3
ii libreoffice-draw 1:4.2.4-3
ii libstdc++6 4.9.0-5
ii libwpd-0.9-9 0.9.9-1
ii libwpg-0.2-2 0.2.2-1
ii libxml2 2.9.1+dfsg1-3
ii uno-libs3 4.2.4-3
ii ure 4.2.4-3
ii zlib1g 1:1.2.8.dfsg-1
Versions of packages libreoffice-impress recommends:
ii libreoffice-avmedia-backend-vlc 1:4.2.4-3
Versions of packages libreoffice-impress suggests:
ii bluez 4.101-4.1
Versions of packages libreoffice-core depends on:
ii fontconfig 2.11.0-5
ii fonts-opensymbol 2:102.6+LibO4.2.4-3
ii libatk1.0-0 2.12.0-1
ii libboost-date-time1.54.0 1.54.0-5
ii libc6 2.18-7
ii libcairo2 1.12.16-2
ii libclucene-contribs1 2.3.3.4-4
ii libclucene-core1 2.3.3.4-4
ii libcmis-0.4-4 0.4.1-7
ii libcups2 1.7.2-3
ii libcurl3-gnutls 7.37.0-1
ii libdbus-1-3 1.8.2-1
ii libdbus-glib-1-2 0.102-1
ii libeot0 0.01-2
ii libexpat1 2.1.0-5
ii libexttextcat-2.0-0 3.4.3-1
ii libfontconfig1 2.11.0-5
ii libfreetype6 2.5.2-1
ii libgcc1 1:4.9.0-5
ii libgdk-pixbuf2.0-0 2.30.7-1
ii libgl1-mesa-glx [libgl1] 10.1.4-1
ii libglib2.0-0 2.40.0-3
ii libglu1-mesa [libglu1] 9.0.0-2
ii libgraphite2-3 1.2.4-2
ii libgtk2.0-0 2.24.23-1
ii libharfbuzz-icu0 0.9.28-2
ii libharfbuzz0b 0.9.28-2
ii libhunspell-1.3-0 1.3.2-7
ii libhyphen0 2.8.6-3
ii libice6 2:1.0.8-2
ii libicu52 52.1-3
ii libjpeg8 8d-2
ii liblangtag1 0.5.1-2
ii liblcms2-2 2.6-1
ii libldap-2.4-2 2.4.39-1
ii libmythes-1.2-0 2:1.2.2-1
ii libneon27-gnutls 0.30.0-2
ii libnspr4 2:4.10.4-1
ii libnspr4-0d 2:4.10.4-1
ii libnss3 2:3.16-1
ii libnss3-1d 2:3.16-1
ii libpango-1.0-0 1.36.3-1
ii libpangocairo-1.0-0 1.36.3-1
ii libpangoft2-1.0-0 1.36.3-1
ii libpng12-0 1.2.50-1
ii librdf0 1.0.17-1+b1
ii libreoffice-common 1:4.2.4-3
ii libsm6 2:1.2.1-2
ii libssl1.0.0 1.0.1g-4
ii libstdc++6 4.9.0-5
ii libx11-6 2:1.6.2-2
ii libxext6 2:1.3.2-1
ii libxinerama1 2:1.1.3-1
ii libxml2 2.9.1+dfsg1-3
ii libxrandr2 2:1.4.2-1
ii libxrender1 1:0.9.8-1
ii libxslt1.1 1.1.28-2
ii libxt6 1:1.1.4-1
ii uno-libs3 4.2.4-3
ii ure 4.2.4-3
ii zlib1g 1:1.2.8.dfsg-1
Versions of packages libreoffice-draw depends on:
ii libavahi-client3 0.6.31-4
ii libavahi-common3 0.6.31-4
ii libc6 2.18-7
ii libcdr-0.0-0 0.0.15-1
ii libdbus-1-3 1.8.2-1
ii libdbus-glib-1-2 0.102-1
ii libetonyek-0.0-0 0.0.4-2
ii libfreehand-0.0-0 0.0.0-3
ii libgcc1 1:4.9.0-5
ii libglib2.0-0 2.40.0-3
ii libicu52 52.1-3
ii liblcms2-2 2.6-1
ii libmspub-0.0-0 0.0.6-1+b1
ii libodfgen-0.0-0 0.0.4-2
ii libreoffice-core 1:4.2.4-3
ii libstdc++6 4.9.0-5
ii libvisio-0.0-0 0.0.31-1+b1
ii libwpd-0.9-9 0.9.9-1
ii libwpg-0.2-2 0.2.2-1
ii libxml2 2.9.1+dfsg1-3
ii uno-libs3 4.2.4-3
ii ure 4.2.4-3
ii zlib1g 1:1.2.8.dfsg-1
Reply to: