Here is an informative article about the flaw which is quite illuminating:
Theoretical attacks yield practical attacks on SSL, PKI.
Note: Extended Validation certificates that cause green or gold address bars in many browsers are also immune to this problem, as EV certificates prohibit the use of MD5. Simply looking for a padlock icon is no longer enough to be sure that communication with the remote server is truly secure.
-- Tom