Three use-of-uninitialized conditions were found in psobjs.c in ps_parser_load_field, in t42parse.c in 42_parse_font_matrix and in t1load.c in tt1_parse_font_matrix.
Created freetype tracking bugs for this issue:
Affects: fedora-all [bug 1262384]
Created mingw-freetype tracking bugs for this issue:
Affects: fedora-all [bug 1262385]
Affects: epel-7 [bug 1262386]
It seems to me that this is already fixed in all maintained versions of Fedora. Check it please.
Upstream freetype git suggests that this issue was addressed in freetype-2.5.3.
Therefore this issue is already fixed in all the maintained versions of Fedora.
CVE-2014-9746 is for accessing uninitialized memory issues
CVE-2014-9747 is for the fix for CWE-372 ("Incomplete Internal State Distinction") issue in the sense that the possibility of immediates-only mode isn't checked (in t42parse.c)