Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attackers to execute arbitrary code via a certain BMP image.
http://www.securityfocus.com/bid/11322
http://lists.apple.com/archives/security-announce/2004/Oct/msg00001.html
http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.html