원문 그대로 올립니다.
아직 vulnerability 문제를 근본적으로 해결한건 아닌것 같네요.
월요일에 release되는 3.4버젼에서 자체적으로 vulnerability문제를 해결한다고 하네요.
가급적 ssh포트를 netfilter로 패킷 필터링하시는것이 좋을듯 싶습니다.
A yet undisclosed vulnerability exists in OpenSSH. You are strongly encouraged to upgrade immediately to OpenSSH 3.3 wit
h the UsePrivilegeSeparation option enabled. Privilege Separation blocks this problem. Keep an eye out for the upcoming
OpenSSH 3.4 release on Monday that fixes the vulnerability itself.