CVE-2008-0032
Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via a movie file containing a Macintosh Resource record with a modified length value in the resource header, which triggers heap corruption.
Date published : 2008-01-15
http://lists.apple.com/archives/security-announce/2008/Jan/msg00001.html