The ProFTPD release notes states:
sean <infamous42md at hotpop.com> found two format
string vulnerabilities, one in mod_sql's SQLShowInfo
directive, and one involving the 'ftpshut' utility. Both
can be considered low risk, as they require active
involvement on the part of the site administrator in order
to be exploited.
These vulnerabilities could potentially lead to information
disclosure, a denial-of-server situation, or execution of
arbitrary code with the permissions of the user running
ProFTPD.