Mailing the story:
Debian alert: New oftpd packages fix denial of service
A vulnerability was discovered in oftpd, an anonymous FTP server, whereby a remote attacker could cause the oftpd process to crash by specifying a large value in a PORT command.