And now the bad guys know there is a very serious vulnerability, somewhere.
Seriously - the entire premise of IT security (no matter the color of your hat) is the assumption that there is no such thing as a secure computer.
[1] http://www.phreedom.org/presentations/reverse-engineering-an...
Edit: Misinterpreted your post. You're right, it's unlikely that they'll guess where it is until a patch comes out.
Then again, IME of many years as a PostgreSQL DBA, the vast, overwhelming majority of postgres shops aren't running anywhere near the latest release, so depending on how far back this vulnerability goes, there could be a very large number of exploitable targets...
it rather works like:
- take exploit
- spread it over the whole internet and calls home where it sticks