Documented security fix in changelog

+- Fixed a security problem that allowed clients to download arbitrary files
+ if the host server was a windows based operating system and the client
+ uses backslashes to escape the directory the files where exposed from.
