OpenSSL contains a flaw related to the SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG workaround in the SSL/TLS server code. The issue is triggered when a remote attacker downgrades the cached ciphersuite, leading to the client using a weaker ciphersuite.
Upgrade to version 0.9.8q or 1.0.0c or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.