Apple issued the patches as part of its 12th security update of the year. By this time last year, Apple released seven fixes, but the company delivered two patches on 11 May, 2006.
The two bugs in the Darwin Streamer Server, Apple’s open-source version of the QuickTime Streaming Server, are caused by stack and heap overflow errors that occur when processing either RTSP (real-time streaming protocol) or SETUP requests, according to a FrSIRT advisory today.
An anonymous researcher reported the flaws to VeriSign iDefense Labs, according to Apple.