Format string vulnerability in log_doit function of Slurp NNTP client 1.1.0 allows a malicious news server to execute arbitrary code on the client via format strings in a server response.
http://www.iss.net/security_center/static/9270.php
http://marc.info/?l=vuln-dev&m=102323341407280&w=2
http://archives.neohapsis.com/archives/bugtraq/2002-06/0014.html