Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
http://www.openbsd.org/advisories/ssh_channelalloc.txt
http://marc.info/?l=bugtraq&m=101586991827622&w=2
http://marc.info/?l=bugtraq&m=101561384821761&w=2