tl;dr Avoid Ubuntu LTS because they don't maintain their packages properly.
tl;dr Avoid Ubuntu LTS because they don't maintain their packages properly.
Since then, both Debian and Ubuntu have acted the same: not knowing about the vulnerability, neither updated their [release] packages. Buster happened to have been updated before it was frozen for release. Stretch was not, and neither was 18.04.
> tl;dr Avoid Ubuntu LTS because they don't maintain their packages properly.
By your logic, you should also avoid Debian then, since they followed the same process here. What got updated and what didn't was merely an accident of calendar freeze dates.
At the time I write this, Debian stretch is still on 1.3.4-1 and hasn't been updated. Ubuntu 18.04 has now been updated.
It's true, I was looking at Debian testing & sid as possibilities but apparently they can't handle mass rebuilds very well and the recommended workaround is to just not update. So rolling distros only for me. (current NixOS)