LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2019-25588

bpftpserver · bulletproof ftp server

Published
CVSS6.2
Severitymedium
WeaknessCWE-1282
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the DNS Address field that allows local attackers to crash the application by supplying an excessively long string. Attackers can enable the DNS Address option in the Firewall settings and paste a buffer of 700 bytes to trigger a crash when the Test function is invoked.

References

← Back to the CVE Tracker

Our coverage of CVE-2019-25588

No stories yet. This page updates automatically when we publish reporting that references CVE-2019-25588.