CVE-2015-2684: Debian Linux

Medium severity, CVSS 4.0. EPSS: 1.9% chance of exploitation in the next 30 days.

Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML message.

Affected products

  • Debian Debian Linux: version 7.0 only
  • Shibboleth Service Provider: up to and including 2.5.3

Published 2015-03-31. Last modified 2026-06-17.