PT-2026-21397 · Unknown · Ccextractor

Oneafter

·

Published

2026-02-21

·

Updated

2026-02-22

·

CVE-2026-2889

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions CCExtractor versions up to 0.96.5
Description A use-after-free issue exists in the processmp4 function within the src/lib ccx/mp4.c library of CCExtractor. This issue is exploitable with local access. The exploit is publicly available.
Recommendations Upgrade to version 0.96.6 or later to address this issue.

Exploit

Fix

Use After Free

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-2889

Affected Products

Ccextractor