This is common for the "enterprise" distributions. They adopt new packages very slowly, preferring to backport security patches. Much to the aggravation of developers who want to be able to use the lates and greatest of something only to find that the RHEL production environment doesn't offer it.
Much to the aggravation of developers who want to be able to use the lates and greatest
Upgrading OpenSSL introduces other problems though -- the OpenSSL developers don't seem to understand the concept of a "stable branch" or "binary compatibility", so importing a new version of OpenSSL can mean that everything which links against it has to be recompiled. This is one of the reasons why FreeBSD doesn't get major OpenSSL updates on stable branches -- our policy is that if a binary worked on X.0, you should be able to run it on all future X.* releases.
Some of these distros are LTS, so the bug fixes are usually back ported. The latest 0.9.8 is y which is from Feburary 2013.