Untrusted search path vulnerability in dash 0.5.4, when used as a login shell, allows local users to execute arbitrary code via a Trojan horse .profile file in the current working directory.
https://exchange.xforce.ibmcloud.com/vulnerabilities/49216
http://www.ubuntu.com/usn/USN-732-1