CVE-2013-4359: ProFTPD

Medium severity, CVSS 5.0. EPSS: 3% chance of exploitation in the next 30 days.

Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation.

Affected products

  • ProFTPD ProFTPD: version 1.3.4 only; version 1.3.5 only

Published 2013-09-30. Last modified 2026-06-16.