Yeah - I would say they should have considered the name a little more, and looked to see what was using the name Slow Loris before putting this out... Whenever I am talking about DoS attacks on webservers, SlowLoris comes up, and this will just add to the confusion.
CM9 RC1 is supposed to be running 4.0.4, right? Shouldn't that have been patched already? Though it also appears they have some bigger issues, like everything you type going out to the debug logs, passwords included.
Ran it on Verizon Galaxy Nexus (4.0.4) and it appears everything is patched. Now if they would just get me Jellybean, I would be a really happy camper...
(Thanks, Captain Hindsight!)