NTP vuln is pretty widespread with many vendors, but how each responds to it is what separates the men from the boys.
The 6.25 rc changelog says it fixes NTP vulnerabilities. Does that mean all previous versions have vulnerabilities? Please share more.
An ideal thing for MT to do would be say "this is a vulnerability, please work around with this firewall rule. It affects versions a,b,c... We're working on a software update."