CVE-2015-2684
Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML message.
Date published : 2015-03-31
http://www.securityfocus.com/bid/73314
https://shibboleth.net/community/advisories/secadv_20150319.txt