From: Yann Ylavic Date: Fri, 8 Feb 2019 10:05:48 +0000 (+0000) Subject: Restore "Changes with Apache 2.4.38" header. X-Git-Tag: 2.4.39~111 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=06b654e8baaa68338838924f69877f4f1dd99e4f;p=thirdparty%2Fapache%2Fhttpd.git Restore "Changes with Apache 2.4.38" header. git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.4.x@1853203 13f79535-47bb-0310-9956-ffa450edef68 --- diff --git a/CHANGES b/CHANGES index 222e011d1a8..cd19f087ed4 100644 --- a/CHANGES +++ b/CHANGES @@ -5,6 +5,8 @@ Changes with Apache 2.4.39 configuration (SSLFIPS on) and not active by default in OpenSSL. PR 63136. [Yann Ylavic] +Changes with Apache 2.4.38 + *) SECURITY: CVE-2018-17199 (cve.mitre.org) mod_session: mod_session_cookie does not respect expiry time allowing sessions to be reused. [Hank Ibell]