The OAuth Spec actually does address white listing redirect_uri's. This threat is discussed in section 4.1.5 of the OAuth 2.0 spec here: http://tools.ietf.org/html/draft-ietf-oauth-v2-threatmodel-0...
Oddly, Facebook has chosen not to follow this recommendation. So any websites that integrate Facebook OAuth must ensure that they contain no open-redirects or they can be hacked in this way. This is worrisome because open-redirects would not otherwise be considered much of a security problem.