Jens,
Okay, thanks for the detailed response.
Only problems:
1. Malicious individuals have better places to look than the e-smith forums for potential holes.
2. Like 1, details of this problem in particular were already posted to bugtraq, securutyresponse, the openssh site itself, slashdot and a host of other sites. Anyone who wanted to know about such things would already do so.
3. Is fair enough, but I'd personally prefer to know about such things, than to imagine that everything is fine until an official patch is released.
4. I think you just hit the nail on the head. While I might not like the policy towards security notifications, I like having access to the e-smith developer release...
Cheers,
James.