Skip to content
Permalink
Browse files

Pass MCRYPT_DEV_URANDOM to mcrypt_create_iv() explicitly

  • Loading branch information...
chinpei215 committed Jan 19, 2018
1 parent 5289aae commit fc397bd4812a8f7e29c6f12ca5cd103d719ea4fd
Showing with 1 addition and 1 deletion.
  1. +1 −1 lib/Cake/Utility/Security.php
@@ -192,7 +192,7 @@ public static function randomBytes($length) {
return openssl_random_pseudo_bytes($length);
}
if (function_exists('mcrypt_create_iv')) {
return mcrypt_create_iv($length);
return mcrypt_create_iv($length, MCRYPT_DEV_URANDOM);
}
trigger_error(
'You do not have a safe source of random data available. ' .

0 comments on commit fc397bd

Please sign in to comment.
You can’t perform that action at this time.