how can you put such an article online, not mentioning that, the actual ssh-daemon-implementation (20.09.03) might be vulnerable to a remote exploit ...
wating for an security update by apple ...
see also: http://lists.netsys.com/pipermail/full-disclosure/2003-September/thread.html#10103