The Berkeley Open Infrastructure for Network Computing (BOINC) client software incorrectly checked the result after calling the RSApublicdecrypt function, allowing a malformed signature to be treated as a good signature rather than as an error. This issue affected the signature checks on RSA keys used with SSL/TLS.
References: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511521
This issue is related with recent OpenSSL's CVE-2008-5077 flaw.