Interestingly just yesterday I got an email from Comodo about a weak SSL certificate advising
how to get it reissued for free. (Which was a useful email because the certificate is on a
system that wasn't vulnerable, but it turns out the key material had been created on a
vulnerable system.)
They're also apparently going to add the vulnerable certificates to their revocation list
soon. Although as you say I'm not sure how widely those revocation lists are checked by
applications.
Ewen