CVE-2019-25588 PUBLISHED

BulletProof FTP Server 2019.0.0.50 Denial of Service via DNS Address

Assigner: VulnCheck
Reserved: 21.03.2026 Published: 22.03.2026 Updated: 22.03.2026

BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the DNS Address field that allows local attackers to crash the application by supplying an excessively long string. Attackers can enable the DNS Address option in the Firewall settings and paste a buffer of 700 bytes to trigger a crash when the Test function is invoked.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor Bpftpserver
Product BulletProof FTP Server
Versions
  • Version 2019.0.0.50 is affected

Credits

  • Victor Mondragón finder

References

Problem Types

  • Assumed-Immutable Data is Stored in Writable Memory CWE