I am perplexed by the latest security patch. It doesn't have its own page but is listed alongside the 10.11.3 update.
The only documented fix for Yosemite is a fix for the libxslt library:
https://support.apple.com/en-us/HT205731
I understand that there is no libxslt.so static library included with Mac OS, which I guess means every binary that uses it has to be updated.
The 2016-001 updater changes 2513 files for a total of 754MB. http://pastebin.com/8xf4ty9W
The only documented fix for Yosemite is a fix for the libxslt library:
libxslt
Available for: OS X Mavericks v10.9.5, OS X Yosemite v10.10.5, and OS X El Capitan v10.11 to v10.11.2
Impact: Visiting a maliciously crafted website may lead to arbitrary code execution
Description: A type confusion issue existed in libxslt. This issue was addressed through improved memory handling.
CVE-ID
CVE-2015-7995 : puzzor
https://support.apple.com/en-us/HT205731
I understand that there is no libxslt.so static library included with Mac OS, which I guess means every binary that uses it has to be updated.
The 2016-001 updater changes 2513 files for a total of 754MB. http://pastebin.com/8xf4ty9W