SquirrelMail 1.4.13 released - older versions compromised
Posted Dec 17, 2007 18:03 UTC (Mon) by proski (subscriber, #104)
[Link]
I'm afraid you don't get it. Saying that the attacker must pick both files means that the attacker would need to influence the original file in addition to the one created by the attacker. If the attacker can add random data to the original tarball, we have a bigger problem, and the checksum is irrelevant.