Both OpenSSH portable versions 3.7p1 and 3.7.1p1 contain multiple vulnerabilities in the new PAM code with at least one of the bugs being remotely exploitable.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/31688/sshpam.adv
Source: https://packetstormsecurity.com/files/31688/sshpam.adv.html

