CVE-2013-4359: ProFTPD
Medium severity, CVSS 5.0. EPSS: 3% chance of exploitation in the next 30 days.
Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation.
Affected products
- ProFTPD ProFTPD: version 1.3.4 only; version 1.3.5 only
Published 2013-09-30. Last modified 2026-06-16.