OpenSSL is one of the two available implementations of the TLS
protocol in Exim. The other is GnuTLS. In the output of { exim
-bV } is a line "Support for:"; if it does not include "OpenSSL"
then you are not affected.
The OpenSSL advisory covers two issues:
(1) CVE-2011-3207: CRL validation with expired CRLs
(2) CVE-2011-3210: TLS ephemeral ECDH crashes
Read the rest at
https://lists.exim.org/lurker/message/20110906.205555.cf73e2ac.en.html
Centos 5.6 has Exim 4.63 and it has OpenSSL
Regards,
Paul.