You don't, unless you trust the source of it, or supply your own.
> I see this with hash values on websites next to ISO and other files.
This doesn't solve the problem you have in mind - verifying the file is genuine; it solves the problem of verifying that what you got is what you expected, i.e. what the site promised. The hash is there so you can detect download errors (used to be a much more frequent thing than it is now). Secondarily, because the files usually sit on a different server than the site itself, the hash lets you detect some cases of your download being tampered with in-flight, or the file itself altered on the server. Not all of such cases, just those where the attacker could affect the download, but couldn't modify the website itself.