ReadCode() in decompress.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (invalid write access) via a crafted HDF5 file. This issue was triggered while converting a GIF file to an HDF file.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-17436.json"