James:
I handed out a CD containing updates with this broken rsync on it at an ALUG meeting, so in this instance I had a responsibility to warn the recipient,
[...]
Yes, in this case it probably was a good idea. In general, though, security alerts are best handled by people who can actually verify them. If you're relying on unsigned messages to open ALUG lists, you've got serious security problems already.
In general, I beg everyone here to sign up to a security alert service from their service company, distributor or a recognised authority.