MD5
(cache) weaknesses have been known for some time now and security researchers have been recommending against its use for a few years, while predicting that a realistic attack was just around the corner. Research was published today that demonstrates that realistic attacks are possible now. The research deals with a proof of concept collision attack to create fake CA certificate using MD5. The researchers state that a knowledgeable attacker can fake a valid signature on a CA certificate, thereby making it possible to hijack the PKI used to sign SSL certs by pretending to be a valid CA. The researchers website MD5 considered harmful today
(cache) has the details. In short, nothing important should use MD5 anymore.