Earlier quoted context omitted.
Unless you are using client side certificates, this one is not your problem. But everybody must upgrade their browsers ASAP.
Is that right? My reading of it is that this affects all cases where you verify the certificate
It's wrong in that this is very much your problem. It's right in that there is nothing you can do about it except hope that all the people who might try to connect to your website are using a patched (or pre-broken) verison of OpenSSL.
Patching your server-side version of OpenSSL (while a good idea) will not solve the problem because certificate verification is done (as it must be) browser-side.