Versions of GDM prior to 2.4.1.6 contain a bug where GDM will run as root
when examining the ~/.xsession-errors file when using the "examine session
errors" feature, allowing local users the ability to read any text file
on the system by creating a symlink. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0547 to this issue.
Additional problems may be found in the X Display Manager Control Protocol
(XDMCP) which allow a denial of service attack (DoS) by crashing the gdm
daemon. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names
CAN-2003-0548 and
CAN-2003-0549 to these issues.