util-vserver before 0.30.208-1 with kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux sets a default policy that trusts unknown capabilities, which could allow local users to conduct unauthorized activities.
https://exchange.xforce.ibmcloud.com/vulnerabilities/25407
http://www.securityfocus.com/bid/17180
http://www.debian.org/security/2006/dsa-1011