Debian Security Advisory DSA 091-1 (ssh)

The remote host is missing an update to ssh announced via advisory DSA 091-1.
If the UseLogin feature is enabled in for ssh local users could pass environment variables (including variables like LD_PRELOAD) to the login process. This has been fixed by not copying the environment of UseLogin is enabled. Please note that the default configuration for Debian does not have the UseLogin enabled. This has been fixed in version 1:1.2.3-9.4.