The proftpd version that was distributed in Debian GNU/Linux 2.1 had several buffer overflow holes that could be exploited by remote attackers.
A short list of problems:
* user input was used in snprintf() without sufficient checks
* An overflow in the log_xfer() routine
* Long pathnames would overflow a buffer
* And more
In addition to the security fixes a couple of Y2K problems were also fixed.
Debian have made a new package with version 1.2.0pre9-4 to address these issues, and Debian recommends that you upgrade your proftpd package immediately.