Furthermore, Secunia doesn't seem to realize that VLC doesn't do static linking on all platforms (lol) -- I mean, why even go after VLC? This was clearly an ffmpeg problem. What a bunch of amateurs.
If your customer gets it from you, then it is your responsibility.
Like I said, the status quo has always been to delegate third-party vulnerabilities or bugs (especially if statically linked) to their respective vendors. The people from VLC were gentlemen for fixing the problem themselves and then upstreaming. I doubt many would disagree.
Edit: To clarify, from what I can tell no one has ever paid even a cent for VLC, though they may have donated to the VideoLAN project.
And regardless of whether you feel that they had any moral responsibility to fix the vulnerability anyway, it's hard to fault VideoLAN here since that is exactly what they did (unless you believe Secunia's side of the story, of course).
However, their blog post makes no mention of that, and they don't seem to question the link between vulnerability PR and actual, verifiable vulnerabilities.
They do complain that Secunia didn't inform or issue an advisory on upstream projects - if VLC had not taken the initiative themselves to upstream the fix then all other apps would still be vulnerable.