That is concerning malleability of the DER encoding only. Note that there are other ways to modify a transaction which change the hash without affecting the signature validity, such as inserting NOP instructions into any of the scriptSig's. That is what I was referring to, and something which was quite obvious from the first release of bitcoind.