> It has never been the responsibility of application developers to fix vulnerabilities in third-party libraries (like, ever)
If your customer gets it from you, then it is your responsibility.
If your customer gets it from you, then it is your responsibility.
Like I said, the status quo has always been to delegate third-party vulnerabilities or bugs (especially if statically linked) to their respective vendors. The people from VLC were gentlemen for fixing the problem themselves and then upstreaming. I doubt many would disagree.
Edit: To clarify, from what I can tell no one has ever paid even a cent for VLC, though they may have donated to the VideoLAN project.
And regardless of whether you feel that they had any moral responsibility to fix the vulnerability anyway, it's hard to fault VideoLAN here since that is exactly what they did (unless you believe Secunia's side of the story, of course).