+1
On everything I'm responsible for, it's assumed that if you've got shell or if you've got permission to upload executable code, you've got the ability to get root.
I'm prepared to keep on top of server security enough to protect against remote-root exploits (with reasonably short zero-day exposure times), but there's no way I'm going to be able to keep every little utility shipped with a useable linux distribution up-to-date and secure.
If Tripwire or Snort or the logfiles show unexpected filesystem changes, we reimage the OS and restore the data from backups.