Notice of potential impact of a heap buffer overflow vulnerability in libwebp / libvpx towards Ricoh products and services
10.01.2024

Notice of potential impact of a heap buffer overflow vulnerability in libwebp / libvpx towards Ricoh products and services

Ricoh understands the importance of security and is committed to managing its products and services with the most advanced security technologies possible for its customers worldwide. 

Ricoh is aware of the reported "Heap buffer overflow vulnerability in libwebp / libvpx"(CVE-2023-4863/5217). 

Heap buffer overflow allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. 

These vulnerabilities are known to be triggered by the use of features for viewing/browsing images and videos. Therefore, please make sure not to use RICOH products or services to view any untrusted sources (URLs or files). 

The impact on Ricoh products and services are currently under investigation. Updates on impacted products and services and related countermeasures will be provided promptly on this page as they become available.

List1:Status and investigation results of this vulnerability's impact on Ricoh's major Products and Services

Product/service typeCategorySubcategoryStatus
Office ProductsMultifunction Printers/CopiersBlack & White MFPPartially affected. Please refer to List 2 below for affected products/services.
Color MFPPartially affected. Please refer to List 2 below for affected products/services.
Wide Format MFPUnder investigation
PrintersBlack & White Laser PrintersNot affected
Color Laser PrintersNot affected
Gel Jet PrintersNot affected
FAXNot affected
Digital DuplicatorsNot affected
ProjectorsNot affected
Video ConferencingNot affected
Interactive WhiteboardsPartially affected. Please refer to List 2 below for affected products/services.
Remote Communication GatesRemote Communication Gate A2Not affected
Remote Communication Gate ANot affected
Remote Communication Gate Type N/L/BN1/BM1Not affected
Software & SolutionsCard Authentication Package SeriesNot affected
Device Manager NX AccountingNot affected
Device Manager NX LiteNot affected
DocuwareNot affected
GlobalScan NXNot affected
Enhanced Locked Print SeriesNot affected
Printer Driver Packager NXNot affected
@Remote Connector NXNot affected
Ricoh Smart Integration (RSI) Platform and its applicationsNot affected
RICOH Print Management CloudNot affected
RICOH Streamline NX V2Not affected
RICOH Streamline NX V3Not affected
Commercial & Industrial PrintingCut sheet PrintersUnder investigation
Wide Format PrintersNot affected
Continuous FeedNot affected
Garment PrinterNot affected
Digital PaintingNot affected
Commercial & Industrial Printing SoftwareNot affected

List2:Ricoh products and services affected by this vulnerability

Product/serviceLink to details
IM 2702

Affected. For details, please refer to the following URL.

https://www.ricoh.com/products/security/vulnerabilities/adv?id=ricoh-prod000009-2023-000003
IM 2500/3000/3500/4000/5000/6000

Affected. For details, please refer to the following URL.

https://www.ricoh.com/products/security/vulnerabilities/adv?id=ricoh-prod000010-2023-000003
IM 370/370F/460F/460FTL

Affected. For details, please refer to the following URL.

https://www.ricoh.com/products/security/vulnerabilities/adv?id=ricoh-prod000160-2023-000003
IM C3010/C3510

Affected. For details, please refer to the following URL.

https://www.ricoh.com/products/security/vulnerabilities/adv?id=ricoh-prod000156-2023-000003
IM C4510/C5510/C6010

Affected. For details, please refer to the following URL.

https://www.ricoh.com/products/security/vulnerabilities/adv?id=ricoh-prod000157-2023-000003
RICOH Interactive Whiteboard Controller Type 2 / Controller Type 3

Affected. For details, please refer to the following URL.

https://www.ricoh.com/products/security/vulnerabilities/adv?id=ricoh-prod000080-2023-000003
Ricoh Interactive Whiteboard Controller OP-10/OP-5/OP-5 Type2

Affected. For details, please refer to the following URL.

https://www.ricoh.com/products/security/vulnerabilities/adv?id=ricoh-prod000079-2023-000003

| Ricoh |

Ricoh tukee digitaalisia työpaikkoja innovatiivisilla teknologioilla ja palveluilla, joiden avulla ihmiset voivat työskennellä älykkäämmin missä tahansa.

Ricoh on 85-vuotisen historiansa aikana kasvattamansa tietämyksen ja organisaatiokyvykkyytensä ansiosta johtava digitaalisten palvelujen ja tiedonhallinnan sekä tulostus- ja kuvantamisratkaisujen toimittaja, joka on suunniteltu tukemaan digitaalista muutosta ja optimoimaan liiketoiminnan suorituskykyä.

Ricoh Groupin pääkonttori sijaitsee Tokiossa, ja sillä on merkittäviä toimintoja ympäri maailmaa, ja sen tuotteet ja palvelut tavoittavat asiakkaita noin 200 maassa ja alueella. Maaliskuussa 2022 päättyneellä tilikaudella Ricoh Groupin maailmanlaajuinen myynti oli 1 758 miljardia jeniä (noin 14,5 miljardia Yhdysvaltain dollaria).

Lisätietoja osoitteessa www.ricoh-europe.com ja www.ricoh.fi

© 2022 RICOH COMPANY, LTD. Kaikki oikeudet pidätetään. Kaikki viitatut tuotenimet ovat vastaavien yritysten tavaramerkkejä.

Lisätietoja:

Ricoh Finland, Myynti ja Markkinointi

Puh. 0207 370 300 (vaihde)

info@ricoh.fi

Sähköposti: markkinointi@ricoh.fi

Kotisivut: www.ricoh.fi 

Seuraa meitä Facebookissa: www.facebook.com/ricohfinland 

Seuraa meitä Twitterissä: https://twitter.com/ricohfin 

Seuraa meitä LinkedInissä: www.linkedin.com/company/ricoh-finland-oy