util-vserver before 0.30.208-1 with kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux sets a default policy that trusts unknown capabilities, which could allow local users to conduct unauthorized activities.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Util-vserver | Vserver | 0 (including) | 0 (including) |
Util-vserver | Vserver | 0.30.209 (including) | 0.30.209 (including) |