Vulnerability ID: 2012-31 Title: Off-by-one error in OpenType Sanitizer Announced Date: April 24, 2012 Reporter: Mateusz Jurczyk Impact: Critical Affected Products: Firefox, Firefox ESR, SeaMonkey, Thunderbird, Thunderbird ESR Fixed in: - Firefox 12 - Firefox ESR 10.0.4 - SeaMonkey 2.9 - Thunderbird 12 - Thunderbird ESR 10.0.4 Description: An off-by-one error in the OpenType Sanitizer (OTS) using the Address Sanitizer tool can lead to out-of-bounds memory errors, uninitialized function pointer execution during parsing, and potential remote code execution. References: - OTS off-by-one may result in arbitrary code execution - Security: Off-by-one in OTS resulting in arbitrary code execution - CVE-2011-3062