Munin is an open source server monitoring tool.
When Munin is compiled with CGI graphics enabled then the files accessible to the www-data user can be overwritten.
A local attacker, by setting multiple upper_limit GET parameters, could overwrite files accessible to the www-user.
There is no known workaround at this time.
All Munin users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-analyzer/munin-2.0.33"