A newly revealed bug in the OpenSSH client from versions 5.4 through 7.1 allows memory contents to be read by malicious servers (archived). The vulnerability exists in code that allows "roaming" which was added to the OpenSSH client but not the OpenSSH server. Patches which remove the roaming code from the OpenSSH client are available.