We released two new security advisories today, regarding the podcast-catching clients prodder and perlpodder.
Both are vulnerable to remote arbitrary command execution by a malicious server, which can append the commands to the URL of the multimedia files.
Red Team makes a good comment about whether the reason few podcatcher exploits have been discovered is because the software is relatively secure, or because no one is looking. I'm betting on the second one.
Can we see more of this in the future? I say "yup!"