A whitelist might not even work. In practice whitelists end up with everything in the world on them. It might not be that hard to find a whitelisted program that would let you do the thing in the article just by passing it the right arguments. Certainly anything with a buffer overflow in it would work and there are probably a hundred other ways to do it too.
Yep, one place where I used to work, the owning company's policy had "Linux" on its whitelist, but not "Wireshark". Even though the company was developing software which communicated over the network in various protocols.