"This is the most serious bug you'll hear about this week: The issue dubbed CVE-0216-0778 has been identified and fixed in the OpenSSH.
An early heads up came from Theo de Raadt in this mailing list posting.
Until you are able to patch affected systems, the recommended workaround is to use"
# echo 'UseRoaming no' > > /etc/ssh/ssh_config
http://undeadly.org/cgi?action=article&sid=20160114142733
updated by @jimmy: 04/23/16 02:14:48AM