[原文]The Java extensions for QuickTime 6.52 and earlier in Apple Mac OS X 10.3.9 allow untrusted applets to call arbitrary functions in system libraries, which allows remote attackers to execute arbitrary code.
Apple QuickTime Java Extensions Untrusted Applet Privilege Escalation
Local Access Required
Loss of Integrity
Mac OS X contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The Java extensions bundled with Quicktime 6.52 and earlier may allow untrusted applets to call arbitrary functions from within system libraries. This flaw may lead to a loss of integrity.
Currently, there are no known workarounds or upgrades to correct this issue. However, Apple has released a patch (Security Update 2005-008) to address this vulnerability.