BulletProof FTP Server Denial-of-Service Vulnerability in Storage-Path Configuration

Vulnerability

A denial-of-service vulnerability has been identified in BulletProof FTP Server version 2019.0.0.50. The issue arises in the Storage-Path configuration parameter, where local attackers can cause the application to crash by inputting an excessively long string. By enabling the Override Storage-Path setting and pasting a buffer of 500 bytes or more, the application fails when attempting to save the configuration.

Impact

Exploiting this vulnerability leads to a crash of the BulletProof FTP Server application, causing a denial-of-service condition.

Reproduction

The vulnerability can be reproduced by running a Python script that generates a 500-byte buffer, which is then copied to the clipboard. After opening BulletProof FTP Server and navigating to the 'Settings' > 'Advanced' menu, the Override Storage-Path option can be enabled. The clipboard content is then pasted into the Storage-Path field, and clicking 'Save' triggers the application to crash.

Added: Mar 22, 2026, 1:24 AM
Updated: Mar 22, 2026, 1:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.6
remediation
0.0
relevance
4.5
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.