The Secure Remote Password (SRP) implementation in Samhain before 2.5.4 does not check for a certain zero value where required by the protocol, which allows remote attackers to bypass authentication via crafted input.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-4773
http://www.securityfocus.com/bid/34003
http://trac.la-samhna.de/samhain/ticket/150