CoreHTTP (up to and including version 0.5.3.1) employs an insufficient input validation method for handling HTTP requests with invalid method names and URIs. Specifically, the vulnerability is an off-by-one buffer overflow in the sscanf() call at file src/http.c line numbers 45 and 46.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/83534/census-2009-0003.txt
Source: https://packetstormsecurity.com/files/83534/CoreHTTP-0.5.3.1-Buffer-Overflow.html

