The only scenario I see this happening is if, upon the creation of a new master password, PasswordSafe encrypts the header (with the old password). This way, when the user enters their new password, PS uses it to decrypt the header, and then uses the old password (stored in the header) to decrypt the database. This would make it easy for someone with access to the old password and the database to simply decrypt it.
Is this how it works? I can't think of any other way it would be able to not re-encrypt the database with the new password. Plus the lingo/acronyms in the paper are going a bit over my head.