[原文]NAI VirusScan NT 4.0.2 does not properly modify the scan.dat virus definition file during an update via FTP, but it reports that the update was successful, which could cause a system administrator to believe that the definitions have been updated correctly.

[CNNVD]NAI VirusScan升级漏洞(CNNVD-199905-011)

        在使用FTP更新病毒库期间,NAI VirusScan NT 4.0.2不能正确的修改scan.dat病毒定义的文件,但是根据报告升级是成功的,该漏洞将导致系统管理员认为定义已正确更新完毕。

NAI VirusScan升级漏洞
中危 未知
1999-05-05 00:00:00 2005-10-20 00:00:00
        在使用FTP更新病毒库期间,NAI VirusScan NT 4.0.2不能正确的修改scan.dat病毒定义的文件,但是根据报告升级是成功的,该漏洞将导致系统管理员认为定义已正确更新完毕。

        Upgrade to VirusScan for Windows NT 4.0.3a or later.

NAI VirusScan NT scan.dat Update Modification Failure
Remote / Network Access Race Condition, Other
Loss of Integrity Upgrade
Exploit Public Vendor Verified, Coordinated Disclosure

- 漏洞描述

VirusScan NT contains a flaw that may cause a user to have out of date virus signatures, making remote context-dependent attacks more successful. The issue is due to the FTP-based update mechanism sometimes failing to properly update the antivirus signatures (in scan.dat), but still indicating that the signatures are updated. This gives the user a false sense of security and outdated signatures.

1998-10-29
1998-10-29 1998-10-29

- 解决方案

Upgrade to version 4.0.3a or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

NAI VirusScan Update Vulnerability
Unknown 169
No Yes
1999-05-05 12:00:00 2009-07-11 12:16:00
This vulnerability was discovered by Simple Nomad <> and published in the NMRC "NAI AntiVirus Update Problem".

- 漏洞讨论

A vulnerability in Network Associates VirusScan for Windows NT stops it from updateting the virus signature definition files under certain conditions while it reports that it is up to date.

NAI's VirusScan features an option that allows the virus signature file to be updates automatically via FTP. A race condition in the code stops the program from correctly updating the definition file yet it fails to notice this error and updates the log as if the file was sucessufully updated and any subsequent updates will inform the user they are up to date. The error cannot be reproduced consistently.

To check that the file is being updated correctly go to the About box fromt he AntiVirus Console and read the latest date next to the text "Created On". If this date does not change after a manual or automatic update you are vulnerable.

- 解决方案

Upgrade to VirusScan for Windows NT 4.0.3a or later.

