Thanks for that. Talk about obscure, I expected to see this on their main page or something. They sure seem to be keeping quiet about this.
If the File version is 6.0.100.65100 or earlier, the file is affected and can be protected by upgrading the software.
I have 6.0.100.65101, so I guess I don't need the patch. The file date is from August of 2007, so I can't say it was patched by one of the recent security fixes my system downloaded. Hrm. Just as well, I wouldn't have liked having to install the Roxio stuff just to enable the patch.