http://blogs.zdnet.com/security/?p=554 It looks like the gmail team has created a fix and pushed the fix. It suggests that you keep checking your filters to see if you been rigged as the fix wouldn't fix it (pun intended).

That's from a year ago. I think TFA is speculating about the same kind of vulnerability, but active now. It is just speculation, though.

I would be curious to know how they fixed it in the first place.

