Buffer overflow in the simplify_path function in config.c for ChBg 1.5 allows remote attackers to execute arbitrary code via a crafted chbg scenario file.
https://exchange.xforce.ibmcloud.com/vulnerabilities/18595
http://www.mandriva.com/security/advisories?name=MDKSA-2005:027