Format string vulnerability in the error handling of IRC invite responses for Trillian 0.725 and 0.73 allows remote IRC servers to execute arbitrary code via an invite to a channel with format string specifiers in the name.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2002-2134
http://www.securityfocus.com/bid/5388