Buffer overflow in IrfanView32 3.07 and earlier allows attackers to execute arbitrary commands via a long string after the "8BPS" image type in a Photo Shop image header.
https://exchange.xforce.ibmcloud.com/vulnerabilities/3549
http://www.securityfocus.com/bid/781