The vulnerable code is in the internal JPX decoder
(JPXStream::readUByte), but Debian builds poppler to use openjpeg instead.
The vulnerable code exists in the source but is not used at runtime.
https://security-tracker.debian.org/tracker/CVE-2017-9083