Home

Description

BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the DNS Address field that allows local attackers to crash the application by supplying an excessively long string. Attackers can enable the DNS Address option in the Firewall settings and paste a buffer of 700 bytes to trigger a crash when the Test function is invoked.

PUBLISHED Reserved 2026-03-21 | Published 2026-03-22 | Updated 2026-03-24 | Assigner VulnCheck




MEDIUM: 6.9CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
MEDIUM: 6.2CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

Assumed-Immutable Data is Stored in Writable Memory

Product status

2019.0.0.50
affected

Credits

Victor Mondragón finder

References

www.exploit-db.com/exploits/46875 (ExploitDB-46875) exploit

bpftpserver.com/ (Official Product Homepage) product

bpftpserver.com/products/bpftpserver/windows/download (Product Reference) product

www.vulncheck.com/...erver-denial-of-service-via-dns-address (VulnCheck Advisory: BulletProof FTP Server 2019.0.0.50 Denial of Service via DNS Address) third-party-advisory

cve.org (CVE-2019-25588)

nvd.nist.gov (CVE-2019-25588)

Download JSON