A critical flaw has been discovered in the PKIX trust components that allows an X509 credential to be trusted in the special case where no trusted names are available for the given entityID. See External References for the complete details.
External References:
http://shibboleth.net/community/advisories/secadv20150225.txt