FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containing an MS-DOS device name such as CON, NUL, COM1, LPT1, and others.
http://www.securityfocus.com/bid/12865
http://sourceforge.net/project/shownotes.php?group_id=21558&release_id=314473