TL;DR: This paper describes an improved preimage attack on the cryptographic hash function MD2 that has complexity equivalent to about 2 evaluations of the MD2 compression function.
Abstract: This paper describes an improved preimage attack on the cryptographic hash function MD2. The attack has complexity equivalent to about 2 evaluations of the MD2 compression function. This is to be compared with the previous best known preimage attack, which has complexity about 2.