What is the absolute WORST CASE senario if this remains un-fixed in OS X? The vulnerability is in a nonexecutable memory location - thus it cannot do anything at all. As someone else posted - put it on the list for “some day” just fore the principal of it. But I see no grand hurry.
Apple letting a known vuln sit around -- for six months after it was fixed in the sources of the OS they use as a foundation -- is inexcusable security policy, and worse PR policy. If their reaction was "oops we missed that", okay, put it in the list of stuff to get done. But "we don't consider that worth fixing", when other respected groups did, is arrogant and unwise, and gets the anti-Apple tech writers all warm and juicy.
I understand quite well that the vuln is not exploitable as things stand today (non-exec memory); that's the only reason it's not a black eye for Apple, but merely an embarrassment.
Fixing security vulns is part of my professional job (I'm Director of System Admin at my company), and I have to make decisions like that every week, and sometimes I let non-critical things wait. But we're not Apple, with tons of anti-Apple writers laying in wait.
I say again, it's not mainly a technical problem. Rather, it was mostly stupid PR to leave this proto-FUD for the tech writers to find and trumpet.