The sbuf_getmsg function in BNC incorrectly handles backspace characters, which could allow remote attackers to bypass authentication and gain access to arbitrary scripts.
https://exchange.xforce.ibmcloud.com/vulnerabilities/17672
http://www.securityfocus.com/bid/11355
http://www.gotbnc.com/changes.html#2.8.9