KDE Security Advisory: KDE version 3.1.3 and below has multiple vulnerabilities in KDM. KDM fails to check for successful completion of the pam_setcred() call which may leave a user with root access. It also has a weak cookie generation algorithm that allows easy brute forcing of session cookies.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/31664/advisory-20030916-1.txt
Source: https://packetstormsecurity.com/files/31664/KDE-Security-Advisory-2003-09-16.1.html

