Recently, I reviewed several Web frameworks and language implementations, and found some vulnerabilities. This is an simple and interesting case, and seems easy to exploit in real world! AffectedAll PHP version PHP 5 < 5.6.33 PHP 7.0 < 7.0.27 PHP 7.1 < 7.1.13 PHP 7.2 < 7.2.1 Vulnerability DetailsThe vulnerability is on the file ext/gd/libgd/gd_gif_in.c. There is a while-loop in LWZReadByte_: 460 d