libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlmbuildtype_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-36949.json"