But then isnt this an issue with Sudo's grace period (ie should it be tied down to that terminal process calling it and not other ones?)
I understand the theoretical issue you present, but lets be honest, its not a vulnerability because to exploit this would require a serious amount of user interaction beforehand
The same can be said for Linux/Solaris, in fact any OS which uses sudo. Hell i think Gnomes GDesklets also could be exploited this was as well, and in the case of them you dont even need to be reminded that the content is bad as firefox just downloads them onto the machine anyway
Jonathan
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/