Yep, there was a known vulbnerabiltiy in formmail that would allow one to execeute shell commands and abuse a mail server.

here is a little blurb.
http://www.ctssn.com/linux/formMailExploit.html