Are you looking for a signature for something in particular or is it the send mail buffer overflow vulnerability that you are referring to? If so, refer to the CERT Advisory http://www.cert.org/advisories/CA-2003-12.html
I guess the signatures for these are available in the IDS systems. I don't have the details though.
From the details of the exploit, this problem is addressed by signature 3115 subsigs 0-2. These are looking for a non-printable character [\x80-\xFF] in the To, From, and CC fields of an email message header. We really only need to identify the \xFF character, but we get the coverage in with the range. Signature 3115 was originally written to cover the other Sendmail exploit in CERT CA-2003-07.