Gentoo Linux Security Advisory GLSA 200710-06 – Moritz Jodeit reported an off-by-one error in the SSL_get_shared_ciphers() function, resulting from an incomplete fix of CVE-2006-3738. A flaw has also been reported in the BN_from_montgomery() function in crypto/bn/bn_mont.c when performing Montgomery multiplication. Versions less than 0.9.8e-r3 are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/59899/glsa-200710-06.txt
Source: https://packetstormsecurity.com/files/59899/Gentoo-Linux-Security-Advisory-200710-6.html

