The same amount of time: it was apparently found with a fuzzer.
If you know `crashme` you already know one fuzzer, which "intended to test the robustness of Unix and Unix-like operating systems by executing random machine instructions." See https://en.wikipedia.org/wiki/Fuzz_testing
As a good app-sec'er you seem to need to be deeply steeped in fuzzer lore. Matasano: "We'll have you write a fuzzer. Everyone here writes fuzzers." http://www.matasano.com/careers/
(I'm obviously not replying to tptacek, just highlighting a bit. ... And basking in the good glow, yes.)
It's much easier to come up with workable exploits in decent time with symbolic input and the stp or z3 solver than with simple fuzzing.