This specific bug in QuickTime could be exploited using a specially crafted web page to cause a buffer overflow vulnerability in order to execute the arbitrary code. So far this is only issue patched by Apple itself. The fix prevents the Quicktime software from launching a malicious RTSP URL by performing additional validation.
Source:
Betanews
Written by: James Delahunty @ 24 Jan 2007 18:31