Info about the vulnerability:
http://www.openssh.org
http://www.openssh.org/txt/iss.adv
http://www.openssh.org/txt/preauth.adv

Dunno if you run snort somewhere on your network, you might want to try these sigs: (the ones about gobbles)
http://www.snort.org/cgi-bin/sigs-search.cgi?sid=ssh