===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata59.html,v
retrieving revision 1.7
retrieving revision 1.8
diff -u -r1.7 -r1.8
--- www/errata59.html 2016/05/01 13:32:35 1.7
+++ www/errata59.html 2016/05/03 14:37:57 1.8
@@ -128,6 +128,22 @@
A source code patch exists which remedies this problem.
+
+005: SECURITY FIX: May 3, 2016
+ All architectures
+Fix issues in the libcrypto library.
+Refer to the advisory.
+
+- Memory corruption in the ASN.1 encoder (CVE-2016-2108)
+
- Padding oracle in AES-NI CBC MAC check (CVE-2016-2107)
+
- EVP_EncodeUpdate overflow (CVE-2016-2105)
+
- EVP_EncryptUpdate overflow (CVE-2016-2106)
+
- ASN.1 BIO excessive memory allocation (CVE-2016-2109)
+
+
+A source code patch exists which remedies this problem.
+
+