Crystal FTP Pro is "a Top awarded FTP client for dummies and experts". A vulnerability in the way Crystal FTP Pro parses incoming LIST responses allows a remote attacker to cause the program to execute arbitrary code.
Credit:
The information has been provided by Luca Ercoli.
Crystal FTP Pro client, does not perform bound checking on the results returned by 'LIST' command. A malicious ftp server, could execute arbitrary code on the target user's client, replies to a 'LIST' command request with a file list that contain a long file extension.