Nine of the 11 vulnerabilities might have allowed an attacker to execute malicious code on a victim's machine.
Several of the flaws can be exploited through maliciously crafted movie files. Such attacks often take the form of e-mail messages with Web links to the malicious files.
Apple's patch comes a week after three security researchers at a Canadian security conference hacking contest managed to compromise a MacBook Air laptop using a zero-day vulnerability.
The exploit took advantage of a hole in Apple's Safari 3.1 Web browser.
TippingPoint Technologies, the sponsor of the contest, said that the vulnerability had been disclosed to Apple and that it would provide no further information about it until the hole was patched.
It's not immediately clear whether the Safari hole was related to QuickTime. TippingPoint Technologies was not immediately available for comment. But Apple did credit TippingPoint researchers for discovering six of the QuickTime flaws it fixed.
QuickTime, like other popular media applications such as Adobe's Flash, represents an appealing target for malicious hackers because it is widely distributed. With Apple's sales on the rise, QuickTime is likely to become even more common.
From the release of QuickTime 7.1.3 in January 2007 through the release of QuickTime 7.3.1 in December of that year, Apple fixed 34 QuickTime vulnerabilities. In 2006, Apple patched 28 QuickTime holes. So far in 2008, Apple has made 16 specific QuickTime repairs.
Stay connected and informed by visiting the CA Solutions Center Community!

Become a member today for instant access to free InformationWeek research, expert advice, peer perspectives, and more on the following topics:
- Application Performance Management (APM)
- Security Management
- Mainframe 2.0
- IT Automation
- Service Assurance
Also, visit our Government and Financial Services groups to see how these technologies apply specifically to those industries.
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.