Debian Security Advisory 1576-1 – The recently announced vulnerability in Debian’s openssl package (DSA-1571-1, CVE-2008-0166) indirectly affects OpenSSH. As a result, all user and host keys generated using broken versions of the openssl package must be considered untrustworthy, even after the openssl update has been applied.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/66400/dsa-1576-1.txt
Source: https://packetstormsecurity.com/files/66400/Debian-Linux-Security-Advisory-1576-1.html

