It is possible in specific circumstances to smash the stack using maliciously crafted input. Upstream bugs: https://github.com/tats/w3m/issues/8 https://github.com/tats/w3m/pull/19 Upstream fix: https://github.com/tats/w3m/commit/67a3db378f5ee3047c158eae4342f7e3245a2ab1 References: http://seclists.org/oss-sec/2016/q4/321
Created w3m tracking bugs for this issue: Affects: fedora-all [bug 1401423] Affects: epel-7 [bug 1401424]