The safe and sane approach is to contact CERT [3,4] through their vulnerability reporting page [5] and let them contact the vendor. If you're curious, the CERT disclosure policy is good reading [6].
[1] http://www.wiretrip.net/p/libwhisker.html
[2] http://www.cert.org/vulnerability-analysis/vul-disclosure.cf...
[5] http://www.kb.cert.org/vuls/html/report-a-vulnerability/
[6] https://www.cert.org/vulnerability-analysis/vul-disclosure.c...