It's always enlightning how some people see how Debian works. Or not. It seems to get more and more common that instead of filing a bugreport people seem to consider it appropriate to rather rant in their blogs about it. That will definitely get things fixed and done and motivates everyone involved to work on the issues that they get notified about only through third-party. And of course it's absolutely alright to change an application directly, not use dpkg-divert or similar, and then complain wildly about how unfair an upgrade of the package replaced that file.
And, Andrew, there wasn't a DSA about CVE-2008-2236 because it was considered a too minor issue for that. Thanks for the fish. Did you btw. try the version from the upcoming lenny release? It's not like it's not directly installable in etch because of dependencies...
Only once I would hope that people that are that deeply involved in Debian (like, being Debian Developers or long-time contributors) would do things like random users do: File the things they are annoyed with, even if they are as minor and awkward as some of the bugreports I receive for wesnoth.