Apple QuickTime is vulnerable to a denial of service, caused by a NULL pointer dereference when the CFRelease() function is invoked. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to cause the application to crash.