---
title: "CVE-2012-2658\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2012-2658?format=md
keywords: index, follow
---

# CVE-2012-2658

Publication date 31 August 2012

Last updated 4 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Buffer overflow in the SQLDriverConnect function in unixODBC 2.3.1 allows
local users to cause a denial of service (crash) via a long string in the
DRIVER option. NOTE: this issue might not be a vulnerability, since the
ability to set this option typically implies that the attacker already has
legitimate access to cause a DoS or execute code, and therefore the issue
would not cross privilege boundaries. There may be limited attack scenarios
if isql command-line options are exposed to an attacker, although it seems
likely that other, more serious issues would also be exposed, and this
issue might not cross privilege boundaries in that context.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2012-2658?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| unixodbc | 17.10 artful | Ignored |
| 17.04 zesty | Ignored end of life |
| 16.10 yakkety | Ignored end of life |
| 16.04 LTS xenial | Ignored |
| 15.10 wily | Ignored end of life |
| 15.04 vivid | Ignored end of life |
| 14.10 utopic | Ignored end of life |
| 14.04 LTS trusty | Ignored |
| 13.10 saucy | Ignored end of life |
| 13.04 raring | Ignored end of life |
| 12.10 quantal | Ignored end of life |
| 12.04 LTS precise | Ignored end of life |
| 11.10 oneiric | Ignored end of life |
| 11.04 natty | Ignored end of life |
| 10.04 LTS lucid | Ignored end of life |
| 8.04 LTS hardy | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [tyhicks](https://launchpad.net/~tyhicks)

This one is likely to be rejected

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

marking as ignored

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2658)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2012-2658)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2012-2658)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2012-2658)

### Other references

* <http://www.openwall.com/lists/oss-security/2012/05/29>
* <https://www.cve.org/CVERecord?id=CVE-2012-2658>
