VDB

ALPINE-CVE-2017-12150

ALPINE-CVE-2017-12150 PUBLISHED CVSS 7.400000095367432 HIGH

It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-the-middle attack and retrieve information in plain-text.

Risk Scores

CVSS v3.1
7.400000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
Alpine:v3.12samba4.1.3-r2, 4.1.4-r0, 4.1.5-r0
Alpine:v3.7samba4.6.6-r1, 0, 3.2.10-r0
Alpine:v3.4samba3.6.5-r0, 3.6.11-r0, 3.6.12-r0
Alpine:v3.15samba3.4.3-r1, 3.4.3-r0, 3.3.7-r4
Alpine:v3.6samba3.3.8-r0, 3.4.3-r0, 3.4.3-r1
Alpine:v3.11samba4.2.9-r0, 4.6.6-r1, 4.6.6-r0
Alpine:v3.17samba4.6.6-r1, 0, 3.2.10-r0
Alpine:v3.16samba3.2.10-r0, 4.1.3-r1, 3.5.4-r1
Alpine:v3.8samba0, 4.6.6-r1, 4.6.6-r0
Alpine:v3.23samba3.2.11-r0, 0, 3.2.10-r0
Alpine:v3.14samba4.1.16-r0, 3.2.10-r0, 3.2.11-r0
Alpine:v3.5samba3.5.6-r1, 3.3.5-r1, 3.2.10-r0
Alpine:v3.21samba3.2.10-r0, 3.2.11-r0, 3.2.11-r1
Alpine:v3.13samba4.6.6-r1, 4.6.6-r0, 4.6.5-r0
Alpine:v3.22samba4.6.6-r1, 0, 3.2.10-r0
Alpine:v3.19samba0, 3.2.11-r0, 3.2.11-r1
Alpine:v3.9samba3.2.10-r0, 3.2.11-r0, 3.2.11-r1
Alpine:v3.10samba4.6.6-r1, 4.6.6-r0, 4.6.5-r0
Alpine:v3.18samba3.4.5-r0, 0, 3.2.11-r1
Alpine:v3.20samba3.2.8-r1, 4.6.6-r0, 4.6.5-r0

Timeline

  • Jul 26, 2018 CVE Published
  • Dec 3, 2025 CVE Updated
  • Apr 30, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›