xdm, with the authComplain variable set to false, allows arbitrary attackers to connect to the X server if the xdm auth directory does not exist.
http://www.redhat.com/support/errata/RHSA-2003-065.html
http://www.redhat.com/support/errata/RHSA-2003-064.html
http://www.iss.net/security_center/static/11389.php
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/55602
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000533