Then, later that year OpenSSH had a critical, remotely exploitable vulnerability that allowed an attacker to gain remote root access. They changed the banner to: "One remote hole in the default install, in nearly 6 years!"
It stayed that way almost 5 more years when in 2007 a flaw in IPv6 was discovered that resulted in a kernel-level buffer overflow, and the banner was updated to: "Only two remote holes in the default install, in a heck of a long time!"
At some point, that slogan was removed, probably because of the fierce criticism and debate it sparked. Even still, OpenBSD pretty much designed the idea of "secure by default" and still to this day, probably lead all modern software OS in this ideology.
I can't think of any other major software distribution where I can count exploits on a single hand after many, many years.