I know I mentioned this the other day but here’s more information. The vulnerability is in QuickTime Player 7.2 and 7.3, and iTunes versions through 7.4.
QuickTime proof-of-concept exploit published:
The exploit can also be used in a Web browser by having the user click on a URL. The attack has been tested against “some of the common Web browsers,” but with Internet Explorer 6/7 and Safari 3 Beta the attack is prevented.Firefox users are not as lucky. Because Firefox allows users to play multimedia files in the QuickTime Player application, the current version of the exploit works perfectly against Firefox if users have chosen QuickTime as the default player for multimedia formats, according to Symantec.