Update for security FAQ

Can someone please add the following to the first item on /security/faq:

  Known culprits are fetchmail (with the mimedecode option enabled) and
  formail (from procmail 3.14 only).


