The following upstream commit was made this week: http://cvs.openssl.org/chngview?cn=16587 This appears to be a single byte overflow, similar to the overflow in SSL_get_shared_ciphers() fixed by CVE-2006-3738 (but this time limited to a single NUL overflow).
*** This bug has been marked as a duplicate of 309801 ***