Heap-based buffer overflow in IrfanView before 4.37 allows remote attackers to execute arbitrary code via the LZW code stream in a GIF file.
https://exchange.xforce.ibmcloud.com/vulnerabilities/89820
https://exchange.xforce.ibmcloud.com/vulnerabilities/89808
http://www.securityfocus.com/bid/64388
http://www.irfanview.com/main_history.htm
http://secunia.com/secunia_research/2013-13/