ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink attack on the (1) MKD or (2) XMKD commands.
http://www.openwall.com/lists/oss-security/2013/01/07/3
http://www.debian.org/security/2013/dsa-2606
http://secunia.com/advisories/51823