PT-2022-7655 · Gpac+1 · Gpac+1

Published

2018-12-19

·

Updated

2024-12-19

·

CVE-2021-4043

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions gpac versions prior to 1.1.0
Description The issue is related to a null pointer dereference in the gpac multimedia platform. This can be exploited to cause a denial of service. The vulnerability is being actively exploited in the wild, with reports of malware, such as "Perfctl", using it for privilege escalation and other malicious activities on Linux servers. The malware can run crypto miners and perform proxyjacking undetected, using a rootkit to evade defense. Thousands of machines running Linux have been infected since 2021.
Recommendations For gpac versions prior to 1.1.0, update to version 1.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the gpac multimedia platform until a patch is applied. Additionally, monitor for suspicious activity related to the "Perfctl" malware and take measures to prevent its execution.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2923
BDU:2024-07871
CVE-2021-4043
DSA-5411-1

Affected Products

Alt Linux
Gpac