Format string vulnerability in the Log_Resolver function in log.c for ngIRCd 0.8.2 and earlier, when compiled with IDENT, logging to SYSLOG, and with DEBUG enabled, allows remote attackers to execute arbitrary code.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-0227
http://www.securityfocus.com/bid/12434
http://www.nosystem.com.ar/advisories/advisory-11.txt