<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Puremessage for UNIX erroring with &amp;quot;SOPHOS_SAVI_ERROR_OLD_VIRUS_DATA&amp;quot; - Update shows OUT OF DATE</title><link>https://community.sophos.com/puremessage/f/discussions/94755/puremessage-for-unix-erroring-with-sophos_savi_error_old_virus_data---update-shows-out-of-date</link><description>Over the weekend we had an issue where our gateways (PMX6.3 on RHEL7) started rejected all emails with the &amp;quot;SOPHOS_SAVI_ERROR_OLD_VIRUS_DATA&amp;quot; when executing against the &amp;quot;Check for Viruses&amp;quot; and &amp;quot;Check for suspicious attachments&amp;quot; policy items. The logging</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Puremessage for UNIX erroring with "SOPHOS_SAVI_ERROR_OLD_VIRUS_DATA" - Update shows OUT OF DATE</title><link>https://community.sophos.com/thread/343602?ContentTypeID=1</link><pubDate>Tue, 08 Aug 2017 18:40:26 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:8052c640-1342-4b48-8edd-2f44eef990c8</guid><dc:creator>Brian Gahan</dc:creator><description>&lt;p&gt;Thanks for the response.&amp;nbsp; I ended up logging a case through Sophos Support.&lt;/p&gt;
&lt;p&gt;Updating to the newer definition file did correct the error (even through the previous definitions were only a couple of days old), but it appears that your coders/developers are writing another date into the definition file which is what the program is looking at to determine definition validity within 120 days.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;For example - The virus definitions that we were running,&amp;nbsp; dated 1st August 2017 (v2017.8.1.5380001) have a &amp;quot;released date&amp;quot; of 2017/04/04.&amp;nbsp; The updated definitions we obtained on Monday, dated 6th August 2017 (v2017.8.6.5400002) have a &amp;quot;released date&amp;quot; of 2017/05/30.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;What i&amp;#39;m saying is that even though the version date is being incremented, if your programmers forget to update the &amp;quot;released date&amp;quot; this problem is going to reoccur 120 days after the 30th May 2017, specifically around the 30th September 2017.&lt;/p&gt;
&lt;p&gt;The issue is resolved now, but it looks like there is an underlying coding/configuration issue at Sophos that has caused this, which should be investigated and corrected.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Puremessage for UNIX erroring with "SOPHOS_SAVI_ERROR_OLD_VIRUS_DATA" - Update shows OUT OF DATE</title><link>https://community.sophos.com/thread/343473?ContentTypeID=1</link><pubDate>Tue, 08 Aug 2017 05:10:28 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:f9d46f35-b173-46a8-a996-07d2cbc3b385</guid><dc:creator>LEFBE</dc:creator><description>&lt;p&gt;Hello Brian,&amp;nbsp;&lt;/p&gt;
&lt;p&gt;SOPHOS_SAVI_ERROR_OLD_VIRUS_DATA indicate that your virus Engine is out of date.&lt;/p&gt;
&lt;p&gt;Could you please provide output of the following command:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;su - pmx6&lt;/li&gt;
&lt;li&gt;wget -c &lt;a href="http://pmx-dynamic.sophos.com/pmx/v6/mainline/linux/IQ.en"&gt;pmx-dynamic.sophos.com/.../IQ.en&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ppm set&lt;/li&gt;
&lt;li&gt;ppm verify --upgrade PureMessage-Sophos-Engine --force&lt;/li&gt;
&lt;li&gt;ppm verify --upgrade PureMessage-Sophos-Data --force&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Explanation:&amp;nbsp;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;change to pmx user (do not forget the sign &lt;span style="color:#ff0000;"&gt;- &lt;/span&gt;)&lt;/li&gt;
&lt;li&gt;try to download IQ.en from repository&lt;/li&gt;
&lt;li&gt;Display PMX repository set into the product&lt;/li&gt;
&lt;li&gt;Force upgrade for both package, Engine, Data&lt;/li&gt;
&lt;/ol&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Puremessage for UNIX erroring with "SOPHOS_SAVI_ERROR_OLD_VIRUS_DATA" - Update shows OUT OF DATE</title><link>https://community.sophos.com/thread/343232?ContentTypeID=1</link><pubDate>Sun, 06 Aug 2017 21:39:43 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:db409dad-70d8-4a56-a9af-7e399569a5ff</guid><dc:creator>Brian Gahan</dc:creator><description>&lt;p&gt;Quick update - Latest definition has been applied (2017.8.6.5400002) which shows the following in the logs:&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;2017-08-07T12:17:09 [28601,Sophos-SAVI,SAVI.pm:46] sophos: loading DATs from /opt/pmx6/etc/data/sophos/2 (was 4): data v2017.8.6.5400002, engine v3.68, SAV v5.40, released 2017/05/30&lt;/p&gt;
&lt;p&gt;So it looks like Sophos have updated the &amp;quot;&lt;strong&gt;released&lt;/strong&gt;&amp;quot; date in the latest definitions, but have only increased it by 8 weeks.&amp;nbsp; Why??&amp;nbsp; Essentially, if this series of events repeats itself without Sophos updating the package again, this issue will re-occur on the 30th September.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>