Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used on systems that do not use '\' or '/' characters for directory separation such as OpenVMS, allows remote authenticated users to overwrite arbitrary files.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2015-7749
http://www.talosintel.com/reports/TALOS-2015-0062/