MEDIUM
BulletProof FTP Server 2019.0.0.50 Denial of Service via DNS Address
Published Mar 22, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.17%
Description
BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the DNS Address field that allows local attackers to crash the application by supplying an excessively long string. Attackers can enable the DNS Address option in the Firewall settings and paste a buffer of 700 bytes to trigger a crash when the Test function is invoked.
Affected products
-
Affected
- 2019.0.0.50
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Bpftpserver | BulletProof FTP Server | unknown | Affected
|
- 2019.0.0.50
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://bpftpserver.com/ product
- http://bpftpserver.com/products/bpftpserver/windows/download product
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-19918 Advisory
- https://www.exploit-db.com/exploits/46875 exploitVDB Entry
- https://www.vulncheck.com/advisories/bulletproof-ftp-server-denial-of-service-via-dns-address third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://bpftpserver.com/ | product | |
| http://bpftpserver.com/products/bpftpserver/windows/download | product | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-19918 | Advisory | |
| https://www.exploit-db.com/exploits/46875 | exploitVDB Entry | |
| https://www.vulncheck.com/advisories/bulletproof-ftp-server-denial-of-service-via-dns-address | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Mar 22, 2026
Updated Oct 1, 2026
Reserved Mar 21, 2026
Link CVE-2019-25588
CISA Vulnrichment
Updated Mar 24, 2026
Red Hat
No data
GitHub
No data