CVE-2019-19977

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
26/12/2019
Last modified:
03/01/2020

Description

libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libesmtp_project:libesmtp:*:*:*:*:*:*:*:* 1.0.6 (including)