While it's not common practice, I strongly believe that for particularly important services, there should be a time delay built into the reset process, so that if a user's email account is compromised in such a way that both the attacker and the victim receive the emails, the victim gets a chance to stop the reset process before any damage is done.