OpenSSH Security Advisory – All versions of OpenSSH’s sshd prior to 3.7 contain a buffer management error which results in a remote root vulnerability.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/31645/buffer.adv
Source: https://packetstormsecurity.com/files/31645/buffer.adv.html