Thanks, I haven't checked if this is in the cvs version of eggdrop, as thats the only version i tend to be using these days.
So there's nothing to be afraid of if you use the most recent version of Eggdrop (currently 1.6.18).
Thanks
It is a known issue, and have been reported to eggheads since long.
I believe there are several different patches for it aswell.

sorry, didn't check the bugzilla, thou i had thought that this bug might of been reported already so i thought i would like to know a bit more about the seriousness of the expliot.
The impact of this bug might be argued, as it would require an attacker to manipulate an user to use a malicious server. Still it's fully exploitable under those conditions.
Yes, i agree. And can see the point, thou i could still say that possibity is deffonatly still out there as there have been troubles with dns fowards to an differant server from some network address.
I assume the patch is saved for a future release of 1.6.19, although I don't know if it has been added to the cvs-repository..
Hope so

thought i've seen alot of projects these days that have problems with expliots in there code. Like anope irc services having alot of problems with there mysql, in my opinion that really caused them alot of bother.

After thinking this through and the means which it takes to expliot eggdrop this way. I would assume that it would probably not happen unless you went to alot of trouble to make it happen. What do you guys think?