It's hard to blame all the rest of us for not doing anything when only Ted knew about this bug for the longest time... *grumble* *grumble*
Brad, I know you read these pages. How did you find this bug in the first place? Was it through a code audit, manual testing or was there a stack trace reported on some bugzilla?
I'm pretty sure that Eugene and Kees track bugzilla entries for security related stack traces. It seems that way from the CVEs they issue.