Authentication is not required to exploit this vulnerability.
The specific flaw exists in the functionality responsible for key exchange. If the sum of specific length fields within a client master key packet exceeds 0x4000, a static buffer can be overflowed leading to arbitrary code execution on the affected system.
Disclosure Timeline:
2008-10-28 - Vulnerability reported to vendor
2011-01-20 - Coordinated public release of advisory