Buffer overflow in the SSL-ready version of linux-ftpd (linux-ftpd-ssl) 0.17 allows remote attackers to execute arbitrary code by creating a long directory name, then executing the XPWD command.
https://exchange.xforce.ibmcloud.com/vulnerabilities/23016
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-3523
http://www.vupen.com/english/advisories/2005/2330
http://www.securityfocus.com/bid/15343
http://www.debian.org/security/2005/dsa-896
http://secunia.com/advisories/17586
http://secunia.com/advisories/17529