The ftpd shipped in the netstd package in Debian GNU/Linux 2.1
(slink) is vulnerable to the widely discussed "setproctitle bug." The
ftpd in the not-yet-released Debian GNU/Linux 2.2 (potato) is also vulnerable.
This problem has been corrected in netstd 3.07-7slink.4 for Debian GNU/Linux 2.1 (slink)
and in ftpd 0.11-8potato.1 for Debian GNU/Linux 2.2 (potato). We recommend upgrading your
ftpd immediately.