So, updating server side OpenSSL will not close this vulnerability (for servers offering https-protected websites)? Is that correct?
If I understand the advisory correctly then this means that somebody could set up a webserver with a specially-crafted certificate and pretend to be somebody else, assuming that the client is running a vulnerable version of OpenSSL.
Is that right? I wish they would write these advisories in a slightly more helpful fashion.