Apple Releases QuickTime 7.4.1 for Leopard, Tiger, and Panther
Visiting a malicious website may lead to an unexpected application termination or arbitrary code execution. A heap buffer overflow exists in QuickTime's handling of HTTP responses when RTSP tunneling is enabled. By enticing a user to visit a maliciously crafted webpage, an attacker may cause an unexpected application termination or arbitrary code execution. This update addresses the issue through improved bounds checking.
For detailed information on the security content of this update, visit this website:
http://www.info.apple.com/kbnum/n61798
QuickTime 7.4.1 for Leopard:
http://www.apple.com/support/downloads/quicktime741forleopard.html
QuickTime 7.4.1 for Tiger:
http://www.apple.com/support/downloads/quicktime741fortiger.html
QuickTime 7.4.1 for Panther:
http://www.apple.com/support/downloads/quicktime741forpanther.html

