Mandriva Linux Security Advisory 2009-037 – Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/74981/MDVSA-2009-037.txt
Source: https://packetstormsecurity.com/files/74981/Mandriva-Linux-Security-Advisory-2009-037.html

