Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allows remote attackers to execute arbitrary code via a long Reason-Phrase response to an rtsp:// request, as demonstrated using a 404 error message.
| Software | From | Fixed in |
|---|---|---|
| apple / quicktime | 7.4 | 7.4.x |
| apple / quicktime | 7.3.1.70 | 7.3.1.70.x |