http://www.openwall.com/lists/oss-security/2015/05/16/3
This was found to be harmless—it can only be exploited by someone who already has write access to the SSH client configuration file.