I found this great explanation of how vendors should respond to security flaws:
Matt's Guide to Vendor Response
If you're a vendor, where vendor is also an Open Source project, it would be worth your time to read this. It has some great tips and is a quick read.