Thing is, there might be some other bug somewhere that would allow an attacker to create just such a directory (e.g. getting access to the same dir through samba or by exploiting a cgi script). Now you're vulnerable to a lot more trouble, so don't assume safety just because one particular bug appears to be more or less innocent.