an attacker can pollute the legitimate image by providing a package list that causes the hash collision." The first part, the command injection bug in Imagebuilder, exists due to the process not ...
In some file types it’s trivial, you just pick the hash ... collision. So how exactly did [David Buchanan] generate that beautiful PNG, which does in fact md5sum to the value in the image?