Quote from ArsTechnica article: http://arstechnica.com/security/2014/06/still-reeling-from-heartbleed-openssl-suffers-from-crypto-bypass-flaw/
edit: Edit to note that Debian Wheezy, CentOS and Arch Linux have already been patched.
For those interested, Debian Security mailing list post...