This vulnerability is disputed by the openssh maintainers, and is considered
expected behavior. As long as scp is used within trusted servers, this
vulnerability should not affect the image.
https://security-tracker.debian.org/tracker/CVE-2019-6110
https://lists.mindrot.org/pipermail/openssh-unix-dev/2019-January/037475.html