A vulnerability exists in all openssh versions 3.6x and earlier. There has been quite a bit of discussion about an exploit in the underground... Reportedly, at least one ISP has been compromised and had disallowed ssh into their servers until a fix was made available. The fixed version is at:
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-3.7p1.tar.gz
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-3.7p1.tar.gz