Debian GNU/Linux is not vulnerable to this when the default setup is kept since such requests are only logged. However, they'll be processed if they come from two well known addresses.
This type of control messages is not needed anymore since the USENET has grown so much and is very reliable. Thus it doesn't hurt to turn this report mechanism off.