Multiple buffer overflows in ircII 20020912 allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via responses that are not properly fed to the mystrcat function by (1) ctcpbuffer, (2) cannotjoinchannel, (3) statusmakeprintable for Statusbar drawing, (4) createserverlist, and possibly other functions.