Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Proftpd | Proftpd | 1.3.4-d (including) | 1.3.4-d (including) |
Proftpd | Proftpd | 1.3.5-rc3 (including) | 1.3.5-rc3 (including) |
Proftpd-dfsg | Ubuntu | lucid | * |
Proftpd-dfsg | Ubuntu | precise | * |
Proftpd-dfsg | Ubuntu | quantal | * |
Proftpd-dfsg | Ubuntu | raring | * |
Proftpd-dfsg | Ubuntu | saucy | * |
Proftpd-dfsg | Ubuntu | upstream | * |