CERT SSHD allows users to override "AllowedAuthentications" configurationthereby permitting users to provide any type of authentication http://www.kb.cert.org/vuls/id/341187
FreeBSD Security Advisory FreeBSD-SA-02:24.k5su k5su utility does not honor `wheel' group ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:24.k5su.asc