CVE-2026-2245Improper Restriction of Operations within the Bounds of a Memory Buffer in Ccextractor

Severity
4.8MEDIUMNVD
EPSS
0.0%
top 95.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 9

Description

A vulnerability was identified in CCExtractor up to 183. This affects the function parse_PAT/parse_PMT in the library src/lib_ccx/ts_tables.c of the component MPEG-TS File Parser. Such manipulation leads to out-of-bounds read. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The name of the patch is fd7271bae238ccb3ae8a71304ea64f0886324925. It is best practice to apply a patch to resolve this issue.

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-w24p-5m2c-jvfh: A vulnerability was identified in CCExtractor up to 1832026-02-09
OSV
CVE-2026-2245: A vulnerability was identified in CCExtractor up to 1832026-02-09

📋Vendor Advisories

1
Debian
CVE-2026-2245: ccextractor - A vulnerability was identified in CCExtractor up to 183. This affects the functi...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-2245 Impact, Exploitability, and Mitigation Steps | Wiz