question about RC bugs on small packages


Not having been around Debian long enough to have seen a complete
release cycle, I have a question.  What should happen to packages
that have RC bugs filed against them (fixed upstream) that nothing
else depends on if the maintainer hasn't dealt with it within a
"reasonable" period of time?

1) removed from testing (drop from Sarge)
2) someone else updates the package
3) Sarge releases with this security bug
4) ?????



