http://mozilla.org/security/shell.html
Bug in Windows versions of Mozilla/Firefox/Thunderbird. Go download now :p It's only the early hours of 9th here, and still the 8th in parts of the USA. Does Microsoft ever get bug fixes out in little over 24 hours of a bug being found? Not that I know of :p I guess the only flaw is the lack of automatic/easy notification/update for the average Joe Bloggs user out there. But then the average user, plus many sysadmins too, obviously don't bother get MS patches either anyway - otherwise the recent IE flaw wouldn't have affected so many servers, so perhaps this "flaw" isn't valid :p