This seems to be an obvious vulnerability, and it's been mentioned in many places (blogs, mailing lists, GNOME bug, Novell bug, Debian bug.) It was first mentioned years ago. It's too bad that after all that, nothing has been done about it.
Posted Feb 13, 2009 10:29 UTC (Fri) by epa (subscriber, #39769)
[Link]
Generally, the more obvious the vulnerability, the less likely it is to get fixed. It will normally be labelled 'expected behaviour' or some other variant of 'we have always done it that way', and left alone.