The ftp_syst function in ftp-basic.c in Free Software Foundation (FSF) GNU wget 1.10.2 allows remote attackers to cause a denial of service (application crash) via a malicious FTP server with a large number of blank 220 responses to the SYST command.
https://www.exploit-db.com/exploits/2947
https://issues.rpath.com/browse/RPL-930
http://www.mandriva.com/security/advisories?name=MDKSA-2007:017