checkpw 1.02 and earlier allows remote attackers to cause a denial of service (infinite loop) via a -- (dash dash) in a username.
http://www.debian.org/security/2015/dsa-3192
http://jvndb.jvn.jp/jvndb/JVNDB-2015-000032
http://jvn.jp/en/jp/JVN34790526/index.html