Actually, it's not, but you might have the responsibility to inform your customers. Consider closed-source libraries.
Like I said, the status quo has always been to delegate third-party vulnerabilities or bugs (especially if statically linked) to their respective vendors. The people from VLC were gentlemen for fixing the problem themselves and then upstreaming. I doubt many would disagree.
It depends. Vendors are obligated to handle upstream vulnerabilities once they become known, and commercial vendors are obligated to handle upstream vulnerabilities no matter what. The only situation in which a vendor can wash their hands of a vulnerability is the one in which they're informed of an upstream vulnerability and the upstream isn't, at which point that vendor is at least obligated to relay it to the upstream.
Edit: To clarify, from what I can tell no one has ever paid even a cent for VLC, though they may have donated to the VideoLAN project.
And regardless of whether you feel that they had any moral responsibility to fix the vulnerability anyway, it's hard to fault VideoLAN here since that is exactly what they did (unless you believe Secunia's side of the story, of course).
If your customer gets it from you, then it is your responsibility.