Mozilla already working on a Firefox 3 security fix
The same day Firefox 3 was shipping, Tipping Point, a research organization for vulnerability analysis and discovery, released an upcoming advisory (ZDI-CAN-349) about a new security vulnerability that could allow an attacker to execute arbitrary code, affecting Firefox 2 and 3 in their Zero Day Initiative site.
Following their own policies, Tipping Point has not disclosed any details about the vulnerability besides it would require user interaction, while Mozilla works on a patch. Mozilla Security reports that there is no known public exploit for this bug at this time.
Once the patch gets landed it will most likely be distributed via Mozilla Update Service as Firefox 3.0.1. Plans for 3.0.1 already include a few dozen stability and performance bug fixes but I wouldn’t be surprised if Mozilla rushes a security update ahead of the usual 4-6 weeks cycle, if it deems the bug severe enough.



Subscribe RSS
Subscribe email

June 20th, 2008 at 3:37 am
I thought they said 10 fucking days?
[Reply]
June 21st, 2008 at 12:22 am
This piece of cr@p is like swiss cheese! Avoid it!
[Reply]
@zzholeJune 21st, 2008 at 11:21 pm
you are dumb
[Reply]