As much as I don't like the fact that someone would publicly post a usable scenario for this vulnerability, I have to say I've been really nervous about the response to this threat. From what I've seen, people were advising each other that addressing the issue could be handled "in time" and that it was not a priority. It most certainly should have been a priority. Flake forced the issue, for the betterment of everyone. (My ignorant opinion.)
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/newsbriefs/779/2542#2542