All versions of OpenSSH’s sshd prior to 3.7 contain a buffer management error. It is uncertain whether this error is potentially exploitable, however, we prefer to see bugs fixed proactively.
From Linux Gentoo…
emerge openssh
What about other unices? Still running older versions?
References:
- Knowledge base at CERT
- CAN-2003-0693