From my limited understanding, the update would be pushed through the security.debian.org repository ASAP, which should be configured by default.
I wonder what the 0.9.8 EOL means for squeeze-lts. Does the Debian LTS team just backport all applicable 1.0.1 patches? Isn't this a little risky? They might not have an intimate understanding of the opaque codebase.
What about Wheezy and Jessie after support for 1.0.1 ends on 31 December?