Notice of potential impact of a heap buffer overflow vulnerability in libwebp / libvpx towards Ricoh products and services
10.01.2024

Notice of potential impact of a heap buffer overflow vulnerability in libwebp / libvpx towards Ricoh products and services

Ricoh understands the importance of security and is committed to managing its products and services with the most advanced security technologies possible for its customers worldwide. 

Ricoh is aware of the reported "Heap buffer overflow vulnerability in libwebp / libvpx"(CVE-2023-4863/5217). 

Heap buffer overflow allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. 

These vulnerabilities are known to be triggered by the use of features for viewing/browsing images and videos. Therefore, please make sure not to use RICOH products or services to view any untrusted sources (URLs or files). 

The impact on Ricoh products and services are currently under investigation. Updates on impacted products and services and related countermeasures will be provided promptly on this page as they become available.

List1:Status and investigation results of this vulnerability's impact on Ricoh's major Products and Services

Product/service typeCategorySubcategoryStatus
Office ProductsMultifunction Printers/CopiersBlack & White MFPPartially affected. Please refer to List 2 below for affected products/services.
Color MFPPartially affected. Please refer to List 2 below for affected products/services.
Wide Format MFPUnder investigation
PrintersBlack & White Laser PrintersNot affected
Color Laser PrintersNot affected
Gel Jet PrintersNot affected
FAXNot affected
Digital DuplicatorsNot affected
ProjectorsNot affected
Video ConferencingNot affected
Interactive WhiteboardsPartially affected. Please refer to List 2 below for affected products/services.
Remote Communication GatesRemote Communication Gate A2Not affected
Remote Communication Gate ANot affected
Remote Communication Gate Type N/L/BN1/BM1Not affected
Software & SolutionsCard Authentication Package SeriesNot affected
Device Manager NX AccountingNot affected
Device Manager NX LiteNot affected
DocuwareNot affected
GlobalScan NXNot affected
Enhanced Locked Print SeriesNot affected
Printer Driver Packager NXNot affected
@Remote Connector NXNot affected
Ricoh Smart Integration (RSI) Platform and its applicationsNot affected
RICOH Print Management CloudNot affected
RICOH Streamline NX V2Not affected
RICOH Streamline NX V3Not affected
Commercial & Industrial PrintingCut sheet PrintersUnder investigation
Wide Format PrintersNot affected
Continuous FeedNot affected
Garment PrinterNot affected
Digital PaintingNot affected
Commercial & Industrial Printing SoftwareNot affected

List2:Ricoh products and services affected by this vulnerability

Product/serviceLink to details
IM 2702

Affected. For details, please refer to the following URL.

https://www.ricoh.com/products/security/vulnerabilities/adv?id=ricoh-prod000009-2023-000003
IM 2500/3000/3500/4000/5000/6000

Affected. For details, please refer to the following URL.

https://www.ricoh.com/products/security/vulnerabilities/adv?id=ricoh-prod000010-2023-000003
IM 370/370F/460F/460FTL

Affected. For details, please refer to the following URL.

https://www.ricoh.com/products/security/vulnerabilities/adv?id=ricoh-prod000160-2023-000003
IM C3010/C3510

Affected. For details, please refer to the following URL.

https://www.ricoh.com/products/security/vulnerabilities/adv?id=ricoh-prod000156-2023-000003
IM C4510/C5510/C6010

Affected. For details, please refer to the following URL.

https://www.ricoh.com/products/security/vulnerabilities/adv?id=ricoh-prod000157-2023-000003
RICOH Interactive Whiteboard Controller Type 2 / Controller Type 3

Affected. For details, please refer to the following URL.

https://www.ricoh.com/products/security/vulnerabilities/adv?id=ricoh-prod000080-2023-000003
Ricoh Interactive Whiteboard Controller OP-10/OP-5/OP-5 Type2

Affected. For details, please refer to the following URL.

https://www.ricoh.com/products/security/vulnerabilities/adv?id=ricoh-prod000079-2023-000003

| About Ricoh |

Ricoh is empowering digital workplaces using innovative technologies and services that enable individuals to work smarter from anywhere.

With cultivated knowledge and organizational capabilities nurtured over its 85-year history, Ricoh is a leading provider of digital services, information management, and print and imaging solutions designed to support digital transformation and optimize business performance.

Headquartered in Tokyo, Ricoh Group has major operations throughout the world and its products and services now reach customers in approximately 200 countries and regions. In the financial year ended March 2022, Ricoh Group had worldwide sales of 1,758 billion yen (approx. 14.5 billion USD).

For further information, please visit www.ricoh-europe.com

© 2023 RICOH COMPANY, LTD. All rights reserved. All referenced product names are the trademarks of their respective companies.

For further information, please contact: 
Ricoh Europe PLC
Charlotte Fernandez
E-mail: media@ricoh-europe.com
Homepage: www.ricoh-europe.com
Join us on Facebook: www.facebook.com/ricoheurope
Follow us on Twitter: www.twitter.com/ricoheurope
Follow us on LinkedIn: http://linkedin.com/company/ricoh-europe

Visit the Ricoh media centre at: www.ricoh-europe.com/press