You get problems like this, but with the amount of overlap in time the different versions provide, with regards to security updates, I'd say its far from unreasonable that one should be able to move over to the next version before stuff like this becomes a problem.
Remind me how long LTS gives you to upgrade to a new version.
If you're waiting until the very end of LTS support to upgrade, you're doing it wrong anyways.
Definitely. But even without LTS, Jessie would be without upstream SSL patches starting 2017. Stretch might not even be released by then. And I wouldn't call the Debian release cycle unreasonably slow.