Nothing in that advisory affects Tor: Tor doesn't use CRLs (or anything else about the CA system), and Tor doesn't use ECDH suites.
We should make sure that our bundles use the latest openssl in any case; throwing this ticket over there. (I believe that erinn is already on this one, though.)
Trac: Owner: N/Ato erinn Component: Tor Client to Tor bundles/installation