A vulnerability has been found in OpenSSL that, given the right conditions,
could lead to the exposure of transactions in plain text. This problem
looks difficult to exploit (it requires a man-in-the-middle attack, among
other things), but one can't be too sure, so the OpenSSL project has
released versions 0.9.7a (with the fix and some new features) and 0.9.6i
(with fixes only). See the announcement for details.