PT-2026-26954 · Unknown · Bulletproof Ftp Server
Victor Mondragón
·
Published
2026-03-22
·
Updated
2026-03-22
·
CVE-2019-25588
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
BulletProof FTP Server version 2019.0.0.50
Description
The software contains a denial of service issue in the DNS Address field. Local attackers can cause the application to crash by providing an excessively long string. Specifically, attackers can enable the DNS Address option within the Firewall settings and paste a 700-byte buffer, triggering a crash when the
Test() function is called.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bulletproof Ftp Server