Debian Security Advisory 1701-1 - It was discovered that OpenSSL does not properly verify DSA signatures on X.509 certificates due to an API misuse, potentially leading to the acceptance of incorrect X.509 certificates as genuine (CVE-2008-5077).
2c2856e8c3bdccd320b3934bc2466311