Format string vulnerability in hsftp 1.11 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via file names containing format string characters that are not properly handled when executing an "ls" command.
https://www.debian.org/security/2004/dsa-447
https://exchange.xforce.ibmcloud.com/vulnerabilities/15276
http://www.securityfocus.com/bid/9715
http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017737.html