Well, to be fair, a number of distros did backport the fix without noticing the vulnerability.
Remote execution aside, sudo did just suffer a comparable issue where new code had been added but not fully vetted. The only real difference to is that I'd expect more from the sudo authors.
Ubuntu, FWIW, doesn't appear to have fixed the original 5.3.9 bug and thus those users may suffer the 5.3.9 DOSing, but hypothetically no remote execution: https://bugs.launchpad.net/bugs/cve/2011-4885