[Bug 1262373] CVE-2014-9746 CVE-2014-9747 freetype: Use of uninitialized memory

bugzilla at redhat.com bugzilla at redhat.com
Tue Sep 29 09:18:52 UTC 2015


https://bugzilla.redhat.com/show_bug.cgi?id=1262373

Adam Mariš <amaris at redhat.com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
            Summary|freetype: Use of            |CVE-2014-9746 CVE-2014-9747
                   |uninitialized memory        |freetype: Use of
                   |                            |uninitialized memory
              Alias|                            |CVE-2014-9746,
                   |                            |CVE-2014-9747



--- Comment #6 from Adam Mariš <amaris at redhat.com> ---
CVE-2014-9746 is for accessing uninitialized memory issues
CVE-2014-9747 is for the fix for CWE-372 ("Incomplete Internal State
Distinction") issue in the sense that the possibility of immediates-only mode
isn't checked (in t42parse.c)

-- 
You are receiving this mail because:
You are on the CC list for the bug.
Unsubscribe from this bug https://bugzilla.redhat.com/token.cgi?t=o4OAm6pQc7&a=cc_unsubscribe


More information about the mingw mailing list