Heap overflow in the KTH Kerberos 4 FTP client 4-1.1.1 allows remote malicious servers to execute arbitrary code on the client via a long response to a passive (PASV) mode request.
http://www.securityfocus.com/bid/4592
http://www.iss.net/security_center/static/8938.php
http://archives.neohapsis.com/archives/bugtraq/2002-04/0339.html