Shooting the messenger (Secunia and VLC)
secunia.com
secunia.com
http://www.jbkempf.com/blog/post/2013/More-lies-from-Secunia
They do complain that Secunia didn't inform or issue an advisory on upstream projects - if VLC had not taken the initiative themselves to upstream the fix then all other apps would still be vulnerable.
Furthermore, Secunia doesn't seem to realize that VLC doesn't do static linking on all platforms (lol) -- I mean, why even go after VLC? This was clearly an ffmpeg problem. What a bunch of amateurs.
If your customer gets it from you, then it is your responsibility.
Edit: To clarify, from what I can tell no one has ever paid even a cent for VLC, though they may have donated to the VideoLAN project.
And regardless of whether you feel that they had any moral responsibility to fix the vulnerability anyway, it's hard to fault VideoLAN here since that is exactly what they did (unless you believe Secunia's side of the story, of course).
Like I said, the status quo has always been to delegate third-party vulnerabilities or bugs (especially if statically linked) to their respective vendors. The people from VLC were gentlemen for fixing the problem themselves and then upstreaming. I doubt many would disagree.
However, their blog post makes no mention of that, and they don't seem to question the link between vulnerability PR and actual, verifiable vulnerabilities.
I wouldn't qualify their incentives as being the same (and VideoLan has no commercial incentive at all by definition).
Money and incentive should have nothing to do it. Is it free, do you make money are questions that do not matter, it is speculation on motive. You either have a bug or you don't and you either have fixed it or you haven't. I would expect engineers worth their salt able to communicate and resolve this for the betterment of everyone and shove their egos to where the sun don't shine.