Debian Security Advisory 1703-1 – It was discovered that BIND, an implementation of the DNS protocol suite, does not properly check the result of an OpenSSL function which is used to verify DSA cryptographic signatures. As a result, incorrect DNS resource records in zones protected by DNSSEC could be accepted as genuine.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/73760/dsa-1703-1.txt
Source: https://packetstormsecurity.com/files/73760/Debian-Linux-Security-Advisory-1703-1.html

