The kernel in FreeBSD 4.x to 4.11 and 5.x to 5.4 does not properly clear certain fixed-length buffers when copying variable-length data for use by applications, which could allow those applications to read previously used sensitive memory.
http://www.vupen.com/english/advisories/2005/2256
http://www.securityfocus.com/bid/15252
http://www.securityfocus.com/bid/13526
http://secunia.com/advisories/17368
http://lists.apple.com/archives/security-announce/2005/Oct/msg00000.html