According to the info page, SSLv2 can only be disabled on OpenSSL by having the right (newer) version of OpenSSL installed. I just checked Debian versions. Wheezy (oldstable): Much to old OpenSSL versions, according to the info site Jessy (stable): Still to old OpenSSL version. Stretch (testing): Still to old OpenSSL version. Sid (unstable): The same version of OpenSSL as Stretch -- Still to old. What to do?
Jessie has 5 changesets on top of 1.0.1k which fix 14 CVE's: http://anonscm.debian.org/viewvc/pkg-openssl/openssl/branche... And similar for the other debian versions.
This is rather in-transparent to me. Would be nice, if somebody could give better advice on this soon.