Stats
- First seen
- June 2024
- Last seen
- August 2026
Description
Detects an image file exploiting a Ghostscript delegate flaw in ImageMagick that runs PostScript commands outside the safety sandbox. The rule matches the document type declarations that public exploits use to reach the interpreter with shell access.