CVE-2018-14551: Critical severity ImageMagick ImageMagick vulnerability
Published Jul 23, 2018
·Updated
Last updated 25 August 2025
Other sources
The ReadMATImageV4 function in coders/mat.c in ImageMagick 7.0.8-7 uses an uninitialized variable, leading to memory corruption.
— Launchpad
Affected Software
3 affected componentsFixes available
ImageMagick ImageMagick=7.0.8-7
Canonical Ubuntu Linux=18.04
debian/imagemagick
8:6.9.11.60+dfsg-1.3+deb11u48:6.9.11.60+dfsg-1.3+deb11u98:6.9.11.60+dfsg-1.6+deb12u58:6.9.11.60+dfsg-1.6+deb12u68:7.1.1.43+dfsg1-1+deb13u48:7.1.1.43+dfsg1-1+deb13u58:7.1.2.13+dfsg1-1
Remediation
Event History
Jul 23, 2018
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:51 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·05:05 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·05:05 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2018-14551?
CVE-2018-14551 is a vulnerability in ImageMagick that allows for memory corruption due to an uninitialized variable.
2
What is the severity of CVE-2018-14551?
CVE-2018-14551 has a severity rating of 9.8 (Critical).
3
How does CVE-2018-14551 affect ImageMagick?
CVE-2018-14551 affects ImageMagick version 7.0.8-7.
4
How can I fix CVE-2018-14551?
To fix CVE-2018-14551, update ImageMagick to version 6.9.10-8 or later.
5
Where can I find more information about CVE-2018-14551?
You can find more information about CVE-2018-14551 at the following references: [Link 1](https://github.com/ImageMagick/ImageMagick/issues/1221), [Link 2](https://lists.debian.org/debian-lts-announce/2020/08/msg00030.html), [Link 3](https://usn.ubuntu.com/3785-1/).