The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.
https://usn.ubuntu.com/4588-1/
https://sourceforge.net/projects/flightgear/files/release-2016.4/
https://sourceforge.net/p/flightgear/flightgear/ci/280cd523686fbdb175d50417266d2487a8ce67d2/
http://www.securityfocus.com/bid/94945
http://www.openwall.com/lists/oss-security/2016/12/16/5
http://www.openwall.com/lists/oss-security/2016/12/15/10