Mozilla may have broken two records. One for the most downloads in a 24 hour period. The second for needing a vulnerability fix only 5 hours after being released. The latter I am sure was not expected. But what the heck. Nobody is perfect and the folks at Mozilla are only human. It is going to be interesting to see how quickly this can be fixed.
TippingPoints / DV Lab reports:
A number of people who monitor our Zero Day Initiative’s Upcoming Advisories page noticed yesterday that we reported a vulnerability to Mozilla (ZDI-CAN-349). Taking into account the coincidental timing of the Firefox 3.0 release, many are asking us if this is the first reported critical vulnerability in the latest version of the popular open source browser.
What we can confirm is that about five hours after the official release of Firefox 3.0 on June 17th, our Zero Day Initiative program received a critical vulnerability affecting Firefox 3.0 as well as prior versions of Firefox 2.0.x. We verified the vulnerability in our lab, acquired it from the researcher, then promptly reported the vulnerability to the Mozilla security team shortly after. Successful exploitation of the vulnerability could allow an attacker to execute arbitrary code. Not unlike most browser based vulnerabilities that we see these days, user interaction is required such as clicking on a link in email or visiting a malicious web page.
I am sure the folks at Mozilla might feel that this could put a damper on their world record for downloads. I don’t believe it will. What is unfortunate is that this was not found before the final release. :-(