Package files are named using the following format:
The version refers to the open source version of the project, while the release refers to Red Hat internal patches to the open source code.
You need to check the release notes to see if RH has backported the require fixes; its what they do
Also, RHEL5 is now on 5.8; you might want to think about updating generally.
Theoretically you could install from src (eg http://www.openssh.com/portable.html
), but then it would not be under rpm/yum ctrl and would also NOT be supported by RH....