The authentication code did not initialize one of the buffers used to calculate the password hashes. This resulted in the use of uninitialized memory when the user provided no password.