The "gpm" package includes a "gpm-root" component which fails to drop its gid root privileges when it executes user commands. "gpm" is a mouse driver for the console, allowing users to cut-and-paste and run commands. A local user could configure their "gpm" instance to launch arbitrary programs with gid of root.
Download the following RPM packages to the NetWinder into a temporary
directory, then install them with the command "rpm -Uvh *.rpm". Be sure
there are no other files ending in ".rpm" in the temporary directory. See
http://www.netwinder.org/security/install.html for more help.