CVE-2017-12150: Debian Linux

High severity, CVSS 7.4. EPSS: 13.2% chance of exploitation in the next 30 days.

It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-the-middle attack and retrieve information in plain-text.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
  • Red Hat Gluster Storage: version 3.0 only
  • Samba Samba: from 3.0.25, before 4.4.16 (fixed in 4.4.16); from 4.5.0, before 4.5.14 (fixed in 4.5.14); from 4.6.0, before 4.6.8 (fixed in 4.6.8)

Published 2018-07-26. Last modified 2026-06-17.