Launched user supplied application still have access to file descriptors.
vulners.com/securityvulns/securityvulns:doc:3494