A NULL pointer dereference flaw was found in libhtp: Under severe memory pressure the decompress code can fail to setup properly. Add checks before dereferencing pointers. Suricata, which embeds libhtp, may also be affected. Upstream patch: https://github.com/inliniac/libhtp/commit/c7c03843cd6b1cbf44eb435d160ba53aec948828
Created suricata tracking bugs for this issue: Affects: fedora-all [bug 1190865]
Created libhtp tracking bugs for this issue: Affects: fedora-all [bug 1190866] Affects: epel-6 [bug 1190867]
libhtp-0.5.6-3.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.