ProFTPD versions below 1.2.9rc3 are susceptible to a couple off-by-one overflows. One was introduced after the patch was written to address the flaws listed here.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/32799/cardinal.txt
Source: https://packetstormsecurity.com/files/32799/cardinal.txt.html

