Unsafe use of g_random_int()

Michael McConville mmcconville at mykolab.com
Sat Aug 22 13:23:46 EDT 2015


Eion Robb wrote:
> Here's a win32 func for you to use instead of /dev/urandom.
> 
> Technically, we're still building to target win2k (even though our GTK
> is only XP or higher), but this patch only works on XP or higher.
> Don't know if that's an issue here, or whether bumping windows version
> requirements is outside of scope for a minor/micro build.

I committed this to my randomness repo yesterday:

	https://hg.pidgin.im/soc/2015/mmcc/rand/rev/dcf27ec371f2

In regards to win2k: we were talking about dropping support for Debian
Squeeze and RHEL 6 in 3.0, so win2k definitely seems like something that
would go. :-)  I've never worked on the Windows side of things, though,
so I don't know how those decisions are made.


More information about the security mailing list