Debian Security Advisory 1185-2: The fix used to correct CVE-2006-2940 introduced code that could lead to the use of uninitialized memory. Such use is likely to cause the application using the openssl library to crash, and has the potential to allow an attacker to cause the execution of arbitrary code.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/50555/dsa-1185-2.txt
Source: https://packetstormsecurity.com/files/50555/Debian-Linux-Security-Advisory-1185-2.html

