A flaw was found in w3m 0.5.3-34. When ~/.w3m is unwritable, w3m uses /tmp in an insecure fashion, which allows a local attacker to craft a symlink attack to overwrite arbitrary files. Upstream patch: https://github.com/tats/w3m/commit/18dcbadf2771cdb0c18509b14e4e73505b242753
Created w3m tracking bugs for this issue: Affects: epel-7 [bug 1539130] Affects: fedora-all [bug 1539129]
Fixed for all the requested releases.