CVE-2019-19977 is a critical stack-based buffer over-read vulnerability in libESMTP versions up to 1.0.6, specifically within the ntlm_build_type_2 function. This flaw allows an unauthenticated attacker to remotely execute arbitrary code, compromise data confidentiality and integrity, and cause denial of service due to its high CVSS score of 9.8. Despite its severity, there is no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.6CPE matchmatch criteria | cpe:2.3:a:libesmtp_project:libesmtp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2019-19977
Jun 11, 2024libesmtp: Stack-based buffer over-read in ntlm_build_type_2() in ntlm/ntlmstruct.c
Dec 26, 2019libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c as demonstrated by a stack-based buffer over-read.
Dec 10, 2019