Andrew Tridgell's message is available at LWN - rsync (1999) and Stuttgart BUGTRAQ - 1999.
Here are some excerpts from Andrew's message to BUGTRAQ:
... released rsync 2.3.1 to fix [the security hole].
A user can't exploit this hole deliberately to gain privileges (ie. this is not an "active" security hole) but a system administrator could ... inadvertently compromise the security of their system.
The fix is to chmod your home directory back to the correct permissions and upgrade to rsync 2.3.1. The bug is in the receiving side of rsync, so it is quite safe to continue to use older anonymous rsync servers as long as you upgrade your client.
This bug has been present in all versions of rsync. I apologize for any inconvenience.