Debian's poppler links against libjpeg which is unaffected by this vulnerability.
The vulnerable code is in Poppler's internal JPEG decoder which Debian does not use.
https://security-tracker.debian.org/tracker/CVE-2017-2814
https://talosintelligence.com/vulnerability_reports/TALOS-2017-0319