Ubuntu Security Notice USN-830-1 – Dan Kaminsky discovered OpenSSL would still accept certificates with MD2 hash signatures. As a result, an attacker could potentially create a malicious trusted certificate to impersonate another site. This update handles this issue by completely disabling MD2 for certificate validation.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/81303/USN-830-1.txt
Source: https://packetstormsecurity.com/files/81303/Ubuntu-Security-Notice-830-1.html