As announced at http://www.proftpd.org/, between November 28 and December 2, the source code for ProFTPD 1.3.3c on the ProFTPD site and all mirrors was compromised.
The proftpd ebuild was bumped to 1.3.3c on November 03, and the Manifest was generated at the same time. I have confirmed that our Manifest matches the "good" version. Also, I looked at a random sample (20) of our mirrors, none offer the compromised version. Gentoo thus is not affected.