Was it the ssl code that the Debian folks 'fixed' to remove all warnings, which then became insecure because it was using illegal buffer overrun reads on stack variables as a source of entropy?

