Not only do you have to patch, you have to re-issue new certificates. About it being unknown is wishful thinking because again there is no way at all to tell if somebody was doing it.
I can assure you there are very smart hackers that are constantly trying to hack SSL. Getting the private keys to the cert is the gold mine jackpot. If somebody looked at the source code for it I'm sure they could easily reverse engineer it and notice the memory problem. Being open source I would assume the source code is readily available?
The cert thing is a definite pain in the ass, but it mostly hits orgs with the resources to deal with it. And as has been said elsewhere, maybe the cost will be a kick in the tail that encourages them to get more involved and put some dollars where their interests lie.
Anyway, I have nothing to go on other than my instinct, which still leans towards "It'll blow over relatively quickly."
