Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation.
http://www.debian.org/security/2013/dsa-2767
http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html
http://lists.opensuse.org/opensuse-updates/2013-10/msg00032.html