It appears that /bin/ls has slipped into the linux-ftpd distribution for Debian as setgid 0. This could possibly be used to leverage root group access.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/54610/ls-setgid.txt
Source: https://packetstormsecurity.com/files/54610/ls-setgid.txt.html

