Amazon Linux AMI Security Advisory: ALAS-2012-99
Advisory Release Date: 2014-09-14 16:32 Pacific
A denial of service flaw was found in the OpenSSH GSSAPI authentication implementation. A remote, authenticated user could use this flaw to make the OpenSSH server daemon (sshd) use an excessive amount of memory, leading to a denial of service. GSSAPI authentication is enabled by default ("GSSAPIAuthentication yes" in "/etc/ssh/sshd_config"). (CVE-2011-5000 )
Run yum update openssh to update your system.