Multiple vulnerabilities are found in Apple QuickTime. A remote attacker could exploit the vulnerabilities by enticing a user to open a specially crafted media file.
Depending on the vulnerability exploited, a successful attack could lead to a denial of service condition, or remote arbitrary code execution.
Apple QuickTime version 7.7.7 is released to address the issues. Users of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk.
The new version of QuickTime is available at:
http://www.apple.com/quicktime/download/
https://support.apple.com/zh-hk/HT204947
https://www.hkcert.org/my_url/en/alert/15070204
https://www.us-cert.gov/ncas/current-activity/2015/06/30/Apple-Releases-Security-Updates-QuickTime-Safari-Mac-EFI-OS-X
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3661 (to CVE-2015-3669)