Though neither TippingPoint, which disclosed the bug to Mozilla privately, nor Mozilla are saying much, the security company reported that the vulnerability requires user interaction and can lead to remote code execution. The bug also affects Firefox 2, and will be addressed with the next security update for both versions of the browser. When asked, Mozilla could not offer a specific date for that. More…