F-Secure’s Weblog has a couple entry on the recent Quicktime troubles, highlighted by the myspace worm. They report two similar vulnerabilities, and their tests has found one of the javascript tricks works with Quicktime users on a Mac with Safari.
Is this vulnerability listed on the eEye Zero Day Tracker? Not so far. Hmmm.